zerion-scan[.]web[.]app
“Crypto Wallet Tracker & Portfolio Tracking | Zerion”
Quan sát đã lưu
Độ tương phản tiêu đề quan sát được
Tóm tắt bằng chứng
PhishDestroy identifies zerion-scan.web.app as an active brand-impersonation phishing domain targeting Zerion users. The site delivers a malicious JavaScript drainer kit disguised as a wallet-scanning tool, coercing victims into connecting wallets and authorizing fraudulent transactions. The kit mimics Zerion’s UI and branding, redirecting traffic from lookalike domains or spoofed ads to harvest private keys, seed phrases, and transaction approvals. At least one open-source drainer script (seed c3eea1) has been observed in live campaigns, increasing the risk of irreversible asset loss once wallet signatures are obtained.
This domain was flagged by two independent security blocklists and is currently blocked by MetaMask and SEAL at the browser extension level. Technical indicators include a VirusTotal detection score of 3/95 security vendors, registration through Google LLC, and resolution to IP 199.36.158.100. The domain uses a Google Trust Services SSL certificate, indicating recent issuance and low-cost domain acquisition. While the creation date is not publicly disclosed, the combination of active SSL issuance, drainer kit deployment, and blocklist presence suggests a newly stood-up phishing operation rather than a long-established threat.
As of the latest scan, zerion-scan.web.app remains active and unblocked by several regional DNS resolvers, presenting an elevated risk to Zerion users searching for legitimate tools. PhishDestroy recommends blocking the domain at the network perimeter and discontinuing any usage of web.app subdomains linked to wallet scanning. Users who may have interacted with this domain should immediately revoke any wallet connections via Zerion’s official app, transfer remaining assets to a cold wallet, and monitor for unauthorized transactions. The remaining risk is heightened due to the domain’s recent activation and partial detection evasion, necessitating continuous monitoring and proactive user education to prevent further compromise.
Data Coverage
Tình báo an ninh mạng
Pipeline ứng phó với các mối đe dọa
Phạm vi danh sách chặn
10 nguồn ngoài được giám sát · ảnh chụp lưu ngày 10/08/2026
Thông tin về tên miền
Chi tiết kỹ thuậtDNS, tên TLS và mốc thời gian
Phân tích của VirusTotal
Phân tích hiệu suất trang
Google PageSpeed Insights — mobile performance audit of zerion-scan.web.app · checked Apr 8, 2026
Bạn có bị ảnh hưởng bởi trang web này không?
Nếu bạn đã nhập thông tin xác thực tài khoản, thông tin cá nhân hoặc thông tin thanh toán hoặc đã tải xuống tệp từ miền này, hãy hành động ngay lập tức. Dưới đây là các nguồn lực giúp bạn báo cáo vụ việc và bảo vệ chính mình.
Hãy báo cáo với chính quyền địa phương
Chọn quốc gia của bạn để nhận liên hệ tội phạm mạng chính thức hoặc soạn thảo đơn khiếu nại →.
Kiểm tra bất kỳ tên miền nào
Phân tích mối đe dọa bằng cách sử dụng danh sách chặn được lưu trữ, WHOIS, DNS và bằng chứng quét công khai
Quét ngayBáo cáo lừa đảo qua email
Hãy gửi các tên miền đáng ngờ đến cơ sở dữ liệu mối đe dọa của chúng tôi — để bảo vệ cộng đồng
Báo cáoDòng tin tức về các mối đe dọa thời gian thực
Các báo cáo lừa đảo gần đây và những thay đổi về tính khả dụng được quan sát thấy
Theo dõiLuôn cập nhật thông tin, luôn an toàn
Theo dõi các mối đe dọa đang diễn ra hoặc phản đối danh sách này nếu bạn cho rằng đây là kết quả báo động sai