zahlcore[.]de
“ZahlCore™ - KI-Trading Deutschland 2025”
Résumé des preuves
Analysis of zahlcore.de indicates a confirmed brand-impersonation phishing domain targeting Binance, currently offline as of July 24, 2026. The domain was registered on February 21, 2026, and resolves to IP address 172.67.143.47, hosted on Cloudflare's infrastructure (AS13335, United States). Infrastructure analysis reveals the use of Cloudflare nameservers (hassan.ns.cloudflare.com and jewel.ns.cloudflare.com), a common tactic to obscure hosting origins and evade takedowns. The domain lacks an SSL certificate, increasing the likelihood of interception or manipulation of user data in transit.
The page title, 'ZahlCore™ - KI-Trading Deutschland 2025,' suggests an attempt to lure German-speaking users with promises of AI-driven trading, a known social-engineering tactic in cryptocurrency scams. While the exact content of the site remains unanalyzed, the combination of the page title and the declared impersonation of Binance aligns with fraudulent investment or credential-harvesting schemes. Gridinsoft assigns a trust score of 0/100, and the domain appears on at least one security blocklist. Six of 93 security vendors on VirusTotal flagged the domain as malicious, providing additional validation of its fraudulent nature.
Defenders should treat this domain as a high-risk indicator of compromise (IOC). Network-level blocking of 172.67.143.47 and the domain itself is recommended, alongside monitoring for related subdomains or newly registered lookalike domains. Given the domain's offline status, further forensic analysis may be limited, but historical DNS and WHOIS records should be preserved for potential law enforcement or incident response activities. The absence of an SSL certificate and the use of Cloudflare nameservers further support the classification of this domain as part of a coordinated phishing campaign.
Data Coverage
Processus de réponse aux menaces Pipeline
Couverture des listes de blocage
10 sources externes surveillées · instantané du 11/08/2026
10 sources externes surveillées Aucune correspondance
Chronologie de détection
-
Cloudflare Radar
Analyse Cloudflare Radar enregistrée · Ouvrir l’analyse
Analyse VirusTotal
Ce site vous a-t-il affecté ?
Si vous avez saisi des informations d'identification de compte, des informations personnelles ou de paiement, ou téléchargé un fichier à partir de ce domaine, agissez immédiatement. Vous trouverez ci-dessous des ressources pour vous aider à signaler l'incident et à vous protéger.
Signalez-le à vos autorités locales
Sélectionnez votre pays pour obtenir contacts officiels en matière de cybercriminalité ou créer un projet de plainte →.
Vérifier n'importe quel domaine
Analyse des menaces à l'aide de listes de blocage stockées, de WHOIS, de DNS et de preuves d'analyse publique
Scanner maintenantSignaler une tentative d'hameçonnage
Signalez les domaines suspects à notre base de données des menaces — protégez la communauté
SignalerFlux d'alertes en temps réel
Rapports de phishing récents et changements de disponibilité observés
SurveillerRestez informés, restez en sécurité
Surveillez les menaces en temps réel ou signalez cette alerte si vous pensez qu'il s'agit d'un faux positif