# PhishDestroy threat dossier — zeroventra.com ================================================================ Fetched: 2026-07-03 17:12:32 UTC Canonical: https://phishdestroy.io/domain/zeroventra.com/ ## VERDICT ---------------------------------------------------------------- ACTIVE THREAT — multiple warning signs Composite threat score: 54/100 (PhishDestroy scoring — see methodology below) ## DETECTION EVIDENCE ---------------------------------------------------------------- VirusTotal: 4/91 security vendors flagged this domain Flagging vendors: alphaMountain.ai, Fortinet, Gridinsoft, SOCRadar AlienVault OTX: 1 pulses (threat-intel feed mentions) Public blocklists: listed on 1 independent blocklist ## INFRASTRUCTURE ---------------------------------------------------------------- IP address: 104.21.65.66 (US, San Francisco) ASN: ASAS13335 CLOUDFLARENET - Cloudflare, Inc., US Hosting org: AS13335 Cloudflare, Inc. Registrar: NICENIC INTERNATIONAL GROUP CO., LIMITED !!! REGISTRAR INTEGRITY ALERT — NiceNIC !!! NiceNIC International: over 90% of its registered domains are associated with illegal content; documented systematic abuse-report non-response. Primary sources: https://phishdestroy.io/nicenic-real https://phishdestroy.io/nicenic-verdict Nameservers: ingrid.ns.cloudflare.com, ram.ns.cloudflare.com Registered: 2026-06-26 Expires: 2027-06-26 Page title: Zeroventra — One workspace. Infinite productivity. HTTP response: 200 ## ABUSE-REPORT HISTORY (evidence of registrar non-response) ---------------------------------------------------------------- Status: pending notification queue. No abuse reports filed yet — this domain is waiting for the next cycle of our automated abuse-reporter. ## TIMELINE ---------------------------------------------------------------- Domain registered: 2026-06-26 (per WHOIS / CT — may reflect a renewal or transfer date, not first-ever registration) First detected: 2026-07-01 06:08:44 UTC (by PhishDestroy tracker) Last verified: 2026-07-03 16:20:36 UTC Current status: ACTIVE / observable ## EXTERNAL CORROBORATION (third-party evidence) ---------------------------------------------------------------- URLScan.io: https://urlscan.io/result/019f1bdc-0023-74af-99a1-387560114716/ Wayback Machine: https://web.archive.org/web/*/zeroventra.com crt.sh CT logs: https://crt.sh/?q=%25.zeroventra.com Google transparency: https://transparencyreport.google.com/safe-browsing/search?url=zeroventra.com AlienVault OTX: https://otx.alienvault.com/indicator/domain/zeroventra.com URLhaus: https://urlhaus.abuse.ch/host/zeroventra.com/ ## ANALYST NARRATIVE ---------------------------------------------------------------- [Generated: 2026-07-01 07:16:18 UTC — narrative may predate facts above. Treat fields in TIMELINE / DETECTION EVIDENCE / INFRASTRUCTURE as authoritative if they differ from the prose below.] The domain zeroventra.com has been identified as a generic phishing threat and is currently in a status of being taken down. This domain uses the page title 'Zeroventra — One workspace. Infinite productivity' to potentially mislead users into believing it is associated with a legitimate productivity platform. The fraudulent nature of this domain indicates attempts to deceive users, likely aiming to harvest sensitive information under the guise of providing workspace productivity solutions. Technical analysis of zeroventra.com reveals it resolves to the IP address 104.21.65.66. The domain was registered through NICENIC INTERNATIONAL GROUP CO., LIMITED, with a creation date set for June 26, 2026. Despite its future creation date, the domain has already been flagged in one threat intelligence pulse on AlienVault OTX and is recognized by 1 of 95 security vendors on VirusTotal as suspicious or malicious. The SSL certificate associated with the domain is issued by Google Trust Services, which could be an attempt to lend credibility to the site. Given its current status of being taken down, users are advised to remain cautious and avoid any interaction with this domain. Organizations should update their security systems to block access to this IP address and monitor for any attempts to access zeroventra.com. Additionally, security teams should educate users about recognizing phishing sites and encourage reporting of suspicious websites to maintain a secure browsing environment. ## EVIDENCE HASHES ---------------------------------------------------------------- Favicon MD5: 46a1f8bdb789e7988a96810d6a475cf1 ## SCORING METHODOLOGY ---------------------------------------------------------------- Composite score is NOT derived from VirusTotal alone. PhishDestroy aggregates: - VirusTotal positive ratio - Public blocklist consensus (MetaMask, ScamSniffer, OpenPhish, PhishTank, URLhaus, CryptoFirewall, SEAL, Polkadot, Enkrypt, Phishunt, DiscordPhishing, PhishingDB) - Cloaking detection (HTTP 666 or rendering delta between bot and real visitor) - DNS-filter consensus (Quad9, CleanBrowsing, NextDNS, AdGuard, Cloudflare, etc.) - AlienVault OTX pulses + Cloudflare Radar + Google Safe Browsing - URLScan / URLQuery verdicts - Brand-impersonation heuristics (DOM analysis of forms, logos, wording) - Known phishing-kit fingerprinting (favicon hash, JS obfuscation signatures) - Wallet-drainer family classification (Angel, MS, Rainbow, Pink, Inferno, ...) - Free-TLS vs paid-cert ratio (throwaway infrastructure signal) - Registrar/hosting abuse history (this registrar's track record) - Human researcher sign-off (operator takedown team) A domain present in our database is ALREADY flagged. A low VT count by itself does NOT mean the domain is safe — new scam domains routinely show 0/95 VT for their first 7–30 days while actively draining wallets. Always cross-reference the composite score and the individual indicators above, not just VT. ## CORRECTIONS / APPEALS ---------------------------------------------------------------- Full HTML report: https://phishdestroy.io/domain/zeroventra.com/ JSON API: https://api.destroy.tools/v1/check?domain=zeroventra.com Appeal a flag: https://phishdestroy.io/appeals/ (responded to within 48 hours, FP rate <0.01%) Submit a report: https://t.me/PhishDestroy_bot About PhishDestroy: independent open-source threat-intelligence platform. Tracked: 174,404 domains (13,154 alive under monitoring, 160,432 confirmed takedowns/dead). Site: https://phishdestroy.io