zeralabs[.]info
“Zera Labs - Zero-Knowledge Digital Cash and Privacy Protocols”
zeralabs.info — Непроверенный. Олицетворение бренда: Across; Тип мошенничества: Seed Phrase Theft. Сводка доказательств: VirusTotal 4/91 (alphaMountain.ai, Chong Lua Dao, Fortinet, Gridinsoft); Spamhaus DBL_PHISH; 1 external blocklist match (ScamSniffer); PhishDestroy score 71/100. Регистратор: NiceNIC.
Подробный анализ PhishDestroy AI ниже оставлен на английском, чтобы сохранить исходную криминалистическую запись.
Analysis of zeralabs.info indicates this domain was actively involved in wallet seed phishing, a scam type explicitly targeting cryptocurrency users. The domain was registered on February 21, 2026, through NiceNIC International Group Co., Limited, and was taken offline by the time of this report on July 24, 2026. Infrastructure analysis reveals the domain resolved to IP address 104.21.15.108, hosted on Cloudflare's network (AS13335) in the United States, with nameservers fred.ns.cloudflare.com and lara.ns.cloudflare.com. The site employed Cloudflare technologies, including HTTP/3, and presented an SSL certificate issued by Google Trust Services (WE1). The page title, 'Zera Labs - Zero-Knowledge Digital Cash and Privacy Protocols,' suggests an attempt to impersonate Across, a known brand in the cryptocurrency or privacy protocol space.
This impersonation aligns with the scam type identified in available intelligence. At the time of detection, three out of ninety-three security vendors on VirusTotal flagged the domain as malicious, and it appeared on two security blocklists. Defensive tools PhishDestroy and ScamSniffer had already blocked access to the domain. While the domain is currently offline, defenders should treat any residual references to zeralabs.info with caution.
Historical DNS and WHOIS records may assist in identifying related infrastructure or campaigns. The use of Cloudflare nameservers and hosting is consistent with phishing operations seeking to obscure origin and evade takedowns. No further details about the exact content or mechanics of the phishing kit are available at this time. Organizations should monitor for similar domains registered through the same registrar or resolving to the same IP range, particularly those leveraging privacy-focused or cryptocurrency-related themes.
Данные сетевой безопасности Registrar context
Процесс реагирования на угрозы
Статус в публичных блок-листах
Сохранённый снимок
Аналитика доменов
Технические сведенияDNS, SAN в протоколе SSL, временные метки
ICANN OVERSIGHT
Аккредитация и контекст RAA
Аккредитация и контекст RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Latest Classified Outcome 2026-08-17 02:51:22 UTC
Технологии · 2 identified
Cloudflare is a web-infrastructure and website-security company, providing content-delivery-network services, DDoS mitigation, Internet security, and distributed domain-name-server services.
www.cloudflare.com 100% уверенностиHTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org 100% уверенностиАнализ VirusTotal
Архивные доказательства
Доказательства и внешние отчеты
Повлиял ли на вас этот сайт?
Если вы ввели учетные данные, личную или платежную информацию или загрузили файл с этого домена, примите немедленные меры. Ниже приведены ресурсы, которые помогут вам сообщить об инциденте и защитить себя.
Сообщите об этом в местные органы власти
Выберите свою страну, чтобы получить официальные контакты по киберпреступности или создать проект жалобы →.
Проверить любой домен
Анализ угроз с использованием сохраненного черного списка, WHOIS, DNS и общедоступных доказательств сканирования.
Сканировать сейчасСообщить о фишинге
Добавляйте подозрительные домены в нашу базу данных угроз — защищайте сообщество
СообщитьПоток оперативных данных об угрозах
Недавние сообщения о фишинге и наблюдаемые изменения доступности
ОтслеживатьБудьте в курсе событий, берегите себя
Отслеживайте актуальные угрозы или оспорьте эту запись, если считаете, что это ложное срабатывание