zenvria[.]com
“Verifying your connection...”
Зведення доказів
This domain, zenvria.com, is confirmed to operate as a credential phishing infrastructure specifically targeting Microsoft users. The site presents a fraudulent login interface designed to harvest account credentials by impersonating Microsoft authentication pages. Analysis of the page title, 'Verifying your connection...,' suggests an attempt to mimic legitimate security verification processes, increasing the likelihood of user deception. The domain is engineered to exploit trust in Microsoft's brand, potentially leading to unauthorized access to corporate or personal accounts, data breaches, and subsequent malicious activities such as lateral movement or financial fraud. Infrastructure analysis reveals multiple technical indicators supporting the phishing classification. The domain was registered on August 20, 2025, through HOSTINGER operations, UAB, and resolves to the IP address 78.111.85.162, located in the Netherlands under AS208951 (ITGLOBAL.COM). At the time of assessment, 19 out of 95 security vendors on VirusTotal flagged zenvria.com as malicious. The domain appears on two independent security blocklists and is currently offline. Notably, the site lacks an SSL certificate, which is atypical for legitimate authentication portals and further signals its fraudulent nature. Users who visited zenvria.com should immediately assume their credentials may have been compromised. Affected individuals should change their Microsoft account passwords using a secure device and enable multi-factor authentication if not already active. Security teams should revoke any active sessions associated with the account and monitor for unauthorized access or anomalous activity. Organizations are advised to block the domain and its associated IP address (78.111.85.162) at the network perimeter to prevent further exposure. If corporate credentials were entered, internal IT teams should be notified to conduct a forensic review of the affected account and systems.
Data Coverage
Розвіддані з мережевої безпеки
Процес реагування на загрози Pipeline
Перевірка за блок-листами
10 зовнішніх джерел під наглядом · знімок від 11.08.2026
Хронологія виявлення
-
Статус домену
Доступний → Недоступний
-
Cloudflare Radar
Сканування Cloudflare Radar збережено · Відкрити сканування
Збережений знімок
Аналітика доменів
Технічні подробиціDNS, імена TLS і часові мітки
ICANN OVERSIGHT
Акредитація та контекст RAA
Акредитація та контекст RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Криміналістичні дані
Аналіз VirusTotal
Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога