The domain portal-netcoinas.zapier.app is currently active and resolves to the IPv4 address 64.239.109.65. VirusTotal analysis shows that six of ninety‑one security vendors have flagged the domain as malicious, indicating a moderate level of detection consensus among scanners. The domain is listed on a single external security blocklist and has been explicitly blocked by the PhishDestroy mitigation service, reinforcing its classification as a phishing threat. Nameserver queries return NS_NOT_FOUND, suggesting that the authoritative name servers are either hidden or not publicly resolvable, which is a common tactic to hinder attribution.
No publicly available SSL/TLS certificate information, registrar details, or page title have been observed, leaving the hosting environment and site content uncharacterized. Consequently, defenders lack visibility into the underlying web application, the presence of credential‑stealing forms, or any brand impersonation. Given the confirmed IP resolution, the IP address should be added to network‑level deny lists and monitored for any anomalous traffic patterns.
Organizations should also block the domain at DNS resolvers and proxy filters, and consider extending existing phishing detection rules to include this host. Continuous re‑scanning of the domain on VirusTotal and periodic checks of blocklist status are advised to capture any changes in detection rates. Until further forensic evidence is obtained, the domain should be treated as high‑risk for credential harvesting and excluded from user access.