zkwasm[.]fi
“zkwasm.fi | 520: Web server is returning an unknown error”
Résumé des preuves
Analysis of the domain zkwasm.fi indicates it is being used for a generic phishing operation and has been taken offline as of the report date, July 24, 2026. The domain was registered on February 21, 2026 and is served from the IP address 188.114.97.3, which belongs to Cloudflare, Inc. (AS13335) and resolves to a United States location. The hosting infrastructure is typical of fast‑flux or abuse‑resilient setups, leveraging Cloudflare's DNS and CDN services; the authoritative nameservers are meilani.ns.cloudflare.com and kianchau.ns.cloudflare.com. The site returned an HTTP 520 error with the page title "zkwasm.fi | 520: Web server is returning an unknown error," suggesting the underlying web server is misconfigured or intentionally obscured.
Security telemetry shows the domain appears on three independent blocklists and has been flagged by PhishDestroy, MetaMask, and SEAL, reinforcing the phishing classification. Reputation scoring from Gridinsoft assigns a zero‑point trust rating (0/100), indicating a complete lack of legitimacy. VirusTotal analysis reports six of ninety‑three scanning engines flagging the domain, providing additional independent confirmation of malicious intent. The SSL certificate is identified only as "WE1," with no further validation details, which is consistent with a low‑trust certificate often observed in malicious deployments.
Defenders should immediately block the domain at perimeter firewalls, DNS resolvers, and endpoint protection solutions. Continuous monitoring of the associated IP address and Cloudflare nameserver patterns is advised, as the infrastructure may be reused for further malicious domains. Adding the domain to internal threat intelligence feeds and sharing the indicator with peer organizations can help accelerate detection of related campaigns.
Data Coverage
Processus de réponse aux menaces Pipeline
Couverture des listes de blocage
10 sources externes surveillées · instantané du 11/08/2026
8 sources externes surveillées Aucune correspondance
Analyse VirusTotal
Ce site vous a-t-il affecté ?
Si vous avez saisi des informations d'identification de compte, des informations personnelles ou de paiement, ou téléchargé un fichier à partir de ce domaine, agissez immédiatement. Vous trouverez ci-dessous des ressources pour vous aider à signaler l'incident et à vous protéger.
Signalez-le à vos autorités locales
Sélectionnez votre pays pour obtenir contacts officiels en matière de cybercriminalité ou créer un projet de plainte →.
Vérifier n'importe quel domaine
Analyse des menaces à l'aide de listes de blocage stockées, de WHOIS, de DNS et de preuves d'analyse publique
Scanner maintenantSignaler une tentative d'hameçonnage
Signalez les domaines suspects à notre base de données des menaces — protégez la communauté
SignalerFlux d'alertes en temps réel
Rapports de phishing récents et changements de disponibilité observés
SurveillerRestez informés, restez en sécurité
Surveillez les menaces en temps réel ou signalez cette alerte si vous pensez qu'il s'agit d'un faux positif