MALICIOUS — CRITICAL
zemowex[.]com
This domain, zemowex.com, is identified as a brand impersonation threat specifically targeting crypto casino and gambling platforms.
- VirusTotal
- 13/95
- Blocklists
- No stored match
- Доступность
- Контент недоступен · HTTP 502
Do not enter credentials, seed phrases, payment details, or personal information on this domain.
Jump to section
zemowex.com — Контент недоступен (HTTP 502). Олицетворение бренда: Cryptoscam; Тип мошенничества: Crypto Scam. Сводка доказательств: VirusTotal 13/95 (ADMINUSLabs, alphaMountain.ai, BitDefender, CyRadar, ESET); URLQuery 100 det.; URLScan malicious verdict; PhishDestroy score 100/100. Регистратор: Key-Systems.
Подробный анализ PhishDestroy AI ниже оставлен на английском, чтобы сохранить исходную криминалистическую запись.
Evidence Analysis
This domain, zemowex.com, is identified as a brand impersonation threat specifically targeting crypto casino and gambling platforms. Analysis of the page title, 'ZEMOWEX | Play at the best online casino based on Blockchain,' confirms the intent to mimic legitimate blockchain-based gambling services. No evidence of a crypto drainer kit was observed, but the domain’s infrastructure and content are designed to deceive users into engaging with fraudulent gambling operations, potentially leading to financial loss or credential compromise.
Infrastructure analysis reveals multiple technical indicators of malicious activity. The domain resolves to IP address 104.21.96.103, hosted on Cloudflare’s network (AS13335), a common obfuscation tactic. It was registered on August 03, 2025, through Key-Systems GmbH, with no SSL certificate present, further reducing trust. VirusTotal reports 13 out of 95 security vendors flagging the domain as malicious, and it appears on one security blocklist. Google Safe Browsing does not currently list the domain, but the combination of these indicators aligns with known brand impersonation campaigns.
As of the latest assessment, zemowex.com has been taken offline, likely due to enforcement actions by security entities. However, the elevated risk level persists due to the domain’s recent creation and the potential for re-emergence under altered infrastructure. Users are advised to avoid interacting with any content associated with this domain, particularly those related to crypto gambling. Organizations should monitor for similar impersonation attempts targeting blockchain-based platforms and implement domain-based blocking for known malicious indicators.
Охват данных13 recorded checks
Сигналы безопасности
Процесс реагирования на угрозы
Статус в публичных блок-листах
Сохранённый снимок
Аналитика доменов
Технические сведенияDNS, SAN в протоколе SSL, временные метки
ICANN OVERSIGHT
Аккредитация и контекст RAA
Аккредитация и контекст RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Анализ VirusTotal
Доказательства и внешние отчетыIndependent lookups and source reports
Victim safety and official reportingImmediate actions and verified reporting channels
Если вы ввели учетные данные, личную или платежную информацию или загрузили файл с этого домена, примите немедленные меры. Ниже приведены ресурсы, которые помогут вам сообщить об инциденте и защитить себя.
Сообщите об этом в местные органы власти
Выберите свою страну, чтобы получить официальные контакты по киберпреступности или создать проект жалобы →.