zkwasm[.]fi
“zkwasm.fi | 520: Web server is returning an unknown error”
zkwasm.fi — Não verificado. Resumo das evidências: VirusTotal 4/91 (alphaMountain.ai, Forcepoint ThreatSeeker, Fortinet, Gridinsoft); PhishDestroy score 71/100.
A análise detalhada do PhishDestroy AI permanece em inglês para preservar o registro forense original.
Analysis of the domain zkwasm.fi indicates it is being used for a generic phishing operation and has been taken offline as of the report date, July 24, 2026. The domain was registered on February 21, 2026 and is served from the IP address 188.114.97.3, which belongs to Cloudflare, Inc. (AS13335) and resolves to a United States location. The hosting infrastructure is typical of fast‑flux or abuse‑resilient setups, leveraging Cloudflare's DNS and CDN services; the authoritative nameservers are meilani.ns.cloudflare.com and kianchau.ns.cloudflare.com. The site returned an HTTP 520 error with the page title "zkwasm.fi | 520: Web server is returning an unknown error," suggesting the underlying web server is misconfigured or intentionally obscured.
Security telemetry shows the domain appears on three independent blocklists and has been flagged by PhishDestroy, MetaMask, and SEAL, reinforcing the phishing classification. Reputation scoring from Gridinsoft assigns a zero‑point trust rating (0/100), indicating a complete lack of legitimacy. VirusTotal analysis reports six of ninety‑three scanning engines flagging the domain, providing additional independent confirmation of malicious intent. The SSL certificate is identified only as "WE1," with no further validation details, which is consistent with a low‑trust certificate often observed in malicious deployments.
Defenders should immediately block the domain at perimeter firewalls, DNS resolvers, and endpoint protection solutions. Continuous monitoring of the associated IP address and Cloudflare nameserver patterns is advised, as the infrastructure may be reused for further malicious domains. Adding the domain to internal threat intelligence feeds and sharing the indicator with peer organizations can help accelerate detection of related campaigns.
Pipeline de resposta a ameaças
Status da lista de bloqueios pública
Análise do VirusTotal
Evidências e relatórios externos
Você foi afetado por este site?
Se você inseriu credenciais de conta, informações pessoais ou de pagamento, ou baixou um arquivo deste domínio, tome medidas imediatas. Abaixo estão os recursos para ajudá-lo a relatar o incidente e se proteger.
Notifique as autoridades locais
Selecione seu país para obter contactos oficiais do cibercrime ou crie um rascunho de reclamação →.
Verificar qualquer domínio
Análise de ameaças usando lista de bloqueio armazenada, WHOIS, DNS e evidências de verificação pública
Digitalize agoraDenunciar phishing
Envie domínios suspeitos para nosso banco de dados de ameaças — proteja a comunidade
DenunciarFeed de ameaças em tempo real
Relatórios recentes de phishing e alterações de disponibilidade observadas
MonitorarMantenha-se informado, mantenha-se seguro
Monitore ameaças em tempo real ou conteste esta listagem caso acredite que se trate de um falso positivo