zenithpay[.]world[.]coinexpressprofittrading[.]xyz
“Zenith Pay”
zenithpay.world.coinexpressprofittrading.xyz — Nội dung không có sẵn (HTTP 502). Mạo danh thương hiệu: Mastercard; Loại lừa đảo: Brand Impersonation. Tóm tắt bằng chứng: VirusTotal 5/93 (CyRadar, Forcepoint ThreatSeeker, Fortinet, Gridinsoft, SOCRadar); PhishDestroy score 65/100.
Phân tích chi tiết của PhishDestroy AI bên dưới được giữ bằng tiếng Anh để bảo toàn hồ sơ pháp chứng gốc.
Analysis of zenithpay.world.coinexpressprofittrading.xyz shows a recently registered domain (creation date February 21, 2026) that resolves to the IP address 192.3.190.186. The host is located in the United States and is advertised as belonging to AS36352, the HostPapa network. The site served an SSL certificate graded R10, and the only visible page element was the title "Zenith Pay," which does not directly reference the targeted brand. The domain is flagged for brand impersonation of Mastercard, and security vendors have recorded five positive detections out of ninety-three scans on VirusTotal.
Independent reputation scoring from Gridinsoft assigned a trust score of zero out of one hundred, indicating a high likelihood of malicious use. The infrastructure has been actively blocked by the PhishDestroy service and appears on a single public security blocklist, suggesting that at least one defensive organization has taken mitigation steps. Current monitoring indicates the domain is offline, and the status field explicitly notes that it has been taken offline.
While the available evidence confirms the domain’s association with Mastercard impersonation, the exact content of the landing page, the presence of credential‑stealing forms, or any post‑compromise payload remain unverified due to the offline status. Defenders should therefore continue to block traffic to the IP 192.3.190.186, add the full domain to internal phishing and brand‑protection blocklists, and monitor the HostPapa ASN for any new subdomains exhibiting similar characteristics. Ongoing vigilance is advised, as the registration date suggests the actor may reuse the same hosting provider for future campaigns targeting payment brands.
Pipeline ứng phó với các mối đe dọa
Trạng thái trong danh sách chặn công khai
Tình báo pháp chứng
Phân tích của VirusTotal
Bằng chứng và các báo cáo bên ngoài
Bạn có bị ảnh hưởng bởi trang web này không?
Nếu bạn đã nhập thông tin xác thực tài khoản, thông tin cá nhân hoặc thông tin thanh toán hoặc đã tải xuống tệp từ miền này, hãy hành động ngay lập tức. Dưới đây là các nguồn lực giúp bạn báo cáo vụ việc và bảo vệ chính mình.
Hãy báo cáo với chính quyền địa phương
Chọn quốc gia của bạn để nhận liên hệ tội phạm mạng chính thức hoặc soạn thảo đơn khiếu nại →.
Kiểm tra bất kỳ tên miền nào
Phân tích mối đe dọa bằng cách sử dụng danh sách chặn được lưu trữ, WHOIS, DNS và bằng chứng quét công khai
Quét ngayBáo cáo lừa đảo qua email
Hãy gửi các tên miền đáng ngờ đến cơ sở dữ liệu mối đe dọa của chúng tôi — để bảo vệ cộng đồng
Báo cáoDòng tin tức về các mối đe dọa thời gian thực
Các báo cáo lừa đảo gần đây và những thay đổi về tính khả dụng được quan sát thấy
Theo dõiLuôn cập nhật thông tin, luôn an toàn
Theo dõi các mối đe dọa đang diễn ra hoặc phản đối danh sách này nếu bạn cho rằng đây là kết quả báo động sai