# zksync07.vip — SUSPICIOUS > zksync07.vip impersonates zkSync and poses a medium phishing risk. Stay alert and avoid this offline domain to protect your assets. ## Summary PhishDestroy identifies zksync07.vip as a brand impersonation domain targeting the zkSync platform, posing a medium risk to users. Such domains often attempt to deceive victims into revealing sensitive information or credentials by mimicking trusted brands, potentially leading to financial loss or account compromise. Vigilance against these threats is crucial to maintaining online security. The domain zksync07.vip was registered on February 21, 2026, through Gname.com Pte. Ltd. It resolves to the IP address 172.67.200.101 and has appeared on three security blocklists. VirusTotal flags this domain with alerts from 3 out of 95 security vendors, indicating suspicious activity. Currently, the domain is offline and returns a 522 Connection Timed Out error, suggesting it is not actively serving phishing content at this time. Users should remain cautious of any communications or links referencing zksync07.vip and avoid visiting this domain. It is recommended to verify URLs carefully before interacting with zkSync-related services and to rely exclusively on official websites and apps. Reporting any suspicious URLs to cybersecurity platforms helps mitigate risks. Regularly updating security software and enabling multi-factor authentication on crypto accounts will further protect users from potential fraud. ## Threat Details - Verdict: SUSPICIOUS - Site status: dead (HTTP 0) - Target brand: zkSync - Page title: zksync07.vip | 522: Connection timed out ## Domain Intelligence - Registered: 2026-02-21 07:01:08 - Registrar: Gname.com Pte. Ltd. - Country: SG - IP: 172.67.200.101 - IP Country: US - IP City: San Francisco - IP Org: AS13335 Cloudflare, Inc. - Nameservers: ["expire1.gname-dns.com", "expire2.gname-dns.com"] - SSL Issuer: none ## Detection Status - VirusTotal: 3 vendors flagged Vendors: ["ChainPatrol", "alphaMountain.ai", "Seclookup"] - Google Safe Browsing: clean - Blocklists: 3 hits Lists: ["PhishDestroy", "MetaMask", "SEAL"] ## Evidence - Screenshot: https://urlscan.io/screenshots/01995f89-a772-74c0-9796-e6df24f8e224.png - Cloudflare Radar: https://radar.cloudflare.com/scan/fb59a2cd-ffc0-460f-a29f-ba6025d48eb3 - PhishDestroy: https://phishdestroy.io/domain/zksync07.vip/ - LLM endpoint: https://phishdestroy.io/domain/zksync07.vip/llm.txt ## If You Visited This Site 1. Change any passwords you may have entered 2. Enable 2FA on all related accounts 3. Monitor your accounts for unauthorized activity 4. Report to: FBI IC3, Europol, local authorities --- Report by PhishDestroy | https://phishdestroy.io/domain/zksync07.vip/ Last updated: 2026-03-19