zerion-scan[.]web[.]app
“Crypto Wallet Tracker & Portfolio Tracking | Zerion”
Збережене спостереження
Зафіксована відмінність заголовків
Зведення доказів
PhishDestroy identifies zerion-scan.web.app as an active brand-impersonation phishing domain targeting Zerion users. The site delivers a malicious JavaScript drainer kit disguised as a wallet-scanning tool, coercing victims into connecting wallets and authorizing fraudulent transactions. The kit mimics Zerion’s UI and branding, redirecting traffic from lookalike domains or spoofed ads to harvest private keys, seed phrases, and transaction approvals. At least one open-source drainer script (seed c3eea1) has been observed in live campaigns, increasing the risk of irreversible asset loss once wallet signatures are obtained.
This domain was flagged by two independent security blocklists and is currently blocked by MetaMask and SEAL at the browser extension level. Technical indicators include a VirusTotal detection score of 3/95 security vendors, registration through Google LLC, and resolution to IP 199.36.158.100. The domain uses a Google Trust Services SSL certificate, indicating recent issuance and low-cost domain acquisition. While the creation date is not publicly disclosed, the combination of active SSL issuance, drainer kit deployment, and blocklist presence suggests a newly stood-up phishing operation rather than a long-established threat.
As of the latest scan, zerion-scan.web.app remains active and unblocked by several regional DNS resolvers, presenting an elevated risk to Zerion users searching for legitimate tools. PhishDestroy recommends blocking the domain at the network perimeter and discontinuing any usage of web.app subdomains linked to wallet scanning. Users who may have interacted with this domain should immediately revoke any wallet connections via Zerion’s official app, transfer remaining assets to a cold wallet, and monitor for unauthorized transactions. The remaining risk is heightened due to the domain’s recent activation and partial detection evasion, necessitating continuous monitoring and proactive user education to prevent further compromise.
Data Coverage
Розвіддані з мережевої безпеки
Процес реагування на загрози Pipeline
Перевірка за блок-листами
10 зовнішніх джерел під наглядом · знімок від 11.08.2026
8 зовнішніх джерел під наглядом Збігів немає
Аналітика доменів
Технічні подробиціDNS, імена TLS і часові мітки
Аналіз VirusTotal
Аналіз продуктивності сайту
Google PageSpeed Insights — mobile performance audit of zerion-scan.web.app · checked Apr 8, 2026
Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога