looginzellepayaccountt-3009dc[.]webflow[.]io
“login Zellepay account | Fast way to get money | Zellepay Login”
looginzellepayaccountt-3009dc.webflow.io — 内容不可用. 品牌冒充:Apple; 诈骗类型:Credential Phishing. 证据摘要: VirusTotal 19/94 (ADMINUSLabs, alphaMountain.ai, BitDefender, CyRadar, DNS8); URLQuery 3 alerts; CF Radar malicious; PhishDestroy score 95/100. 注册商: Webflow.
为保留原始取证记录,下方的 PhishDestroy AI 详细分析仍使用英文。
This domain, looginzellepayaccountt-309dc.webflow.io, is identified as a banking phishing resource specifically designed to impersonate the Zelle payment platform. Analysis confirms the domain was actively harvesting user credentials through a fraudulent login interface under the page title 'login Zellepay account | Fast way to get money | Zellepay Login.' The domain is currently offline, but prior activity indicates a targeted threat against financial account holders. Infrastructure analysis reveals the domain was registered through Webflow on March 07, 2026, and resolved to the IP address 172.64.151.8, hosted on AS13335 (Cloudflare, Inc.). Security validation shows 19 of 95 VirusTotal vendors flagged the domain as malicious, with an additional presence on one security blocklist. The SSL certificate, issued by Google Trust Services (WE1), provided a false sense of legitimacy while facilitating encrypted credential theft. The domain's creation date suggests either a premature registration or a typo, as it predates the current date by several years, a tactic occasionally used to evade detection. Current status indicates the domain has been taken offline, likely due to enforcement action or hosting suspension. However, the infrastructure remains a residual risk, particularly if reactivated or mirrored on alternate domains. Users who accessed the site are advised to immediately reset Zelle and associated banking credentials, enable multi-factor authentication, and monitor financial statements for unauthorized transactions. Organizations should update web filtering rules to block the domain and its resolved IP, while security teams should investigate any prior connections to 172.64.151.8 for potential compromise indicators.
网络安全情报
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| DNS4EU | looginzellepayaccountt-3009dc.webflow.io |
malicious | Sinkholed |
| Cloudflare DNS | looginzellepayaccountt-3009dc.webflow.io |
malicious | Sinkholed |
| OpenDNS | looginzellepayaccountt-3009dc.webflow.io |
phishing | Phishing Block |
威胁响应 Pipeline
公共封禁名单状态
所用技术 · 3 identified
Cloudflare is a web-infrastructure and website-security company, providing content-delivery-network services, DDoS mitigation, Internet security, and distributed domain-name-server services.
www.cloudflare.com 置信度 100%HTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org 置信度 100%VirusTotal 分析
存档证据
证据与外部报告
您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。