zapper-nft[.]io
“Zapper”
Observation enregistrée
Contraste de titres observé
Résumé des preuves
This domain, zapper-nft.io, was observed to resolve to the IP address 104.21.32.1, which is owned by Cloudflare, Inc. (AS13335) and geolocated to the United States. The authoritative name servers are demi.ns.cloudflare.com and ned.ns.cloudflare.com, indicating that the domain is hosted behind Cloudflare’s edge network. Registration information shows the domain was created on August 06, 2025 and was purchased through Dynadot LLC. No SSL certificate was presented during connection attempts, and the site returned an HTTP response indicating it is currently taken offline. The page title returned by the server is “Zapper”, which does not correspond to the targeted brand. However, threat intelligence classifies the activity as a brand impersonation campaign targeting the foundation brand, and the domain name has been flagged accordingly.
VirusTotal analysis recorded three detections out of ninety‑five scanned security vendors, confirming that at least a subset of scanners identified malicious characteristics. Independent security services have also listed the domain on a single blocklist, and PhishDestroy has recorded it as blocked. The Gridinsoft trust score of zero out of one hundred further reflects a high confidence of malicious intent. The combination of a recent registration, use of a reputable CDN service without TLS, a generic page title, and multiple vendor detections aligns with typical infrastructure patterns employed in brand‑impersonation operations.
Because the domain is presently offline, direct content inspection could not be performed, leaving the exact phishing payload and user‑facing elements unverified. Defenders should continue to block the IP address 104.21.32.1 for traffic originating from zapper-nft.io, add the domain to internal deny lists, and monitor for any re‑registration attempts or related sub‑domains using the same Cloudflare name servers. Ongoing observation of the associated ASN and registrar may reveal future infrastructure reuse.
Data Coverage
Processus de réponse aux menaces Pipeline
Couverture des listes de blocage
10 sources externes surveillées · instantané du 11/08/2026
10 sources externes surveillées Aucune correspondance
Chronologie de détection
-
Cloudflare Radar
Analyse Cloudflare Radar enregistrée · Ouvrir l’analyse
Analyse VirusTotal
Ce site vous a-t-il affecté ?
Si vous avez saisi des informations d'identification de compte, des informations personnelles ou de paiement, ou téléchargé un fichier à partir de ce domaine, agissez immédiatement. Vous trouverez ci-dessous des ressources pour vous aider à signaler l'incident et à vous protéger.
Signalez-le à vos autorités locales
Sélectionnez votre pays pour obtenir contacts officiels en matière de cybercriminalité ou créer un projet de plainte →.
Vérifier n'importe quel domaine
Analyse des menaces à l'aide de listes de blocage stockées, de WHOIS, de DNS et de preuves d'analyse publique
Scanner maintenantSignaler une tentative d'hameçonnage
Signalez les domaines suspects à notre base de données des menaces — protégez la communauté
SignalerFlux d'alertes en temps réel
Rapports de phishing récents et changements de disponibilité observés
SurveillerRestez informés, restez en sécurité
Surveillez les menaces en temps réel ou signalez cette alerte si vous pensez qu'il s'agit d'un faux positif