zerogastrx[.]trade
“ZeroGas TRX - Send USDT Without TRX Balance”
zerogastrx.trade — 服务器错误 (HTTP 502). 品牌冒充:Ledger; 诈骗类型:Crypto Scam. 证据摘要: VirusTotal 3/94 (Fortinet, SOCRadar, ThreatHive); Spamhaus DBL_SPAM; 2 external blocklist matches (MetaMask, SEAL); PhishDestroy score 66/100. 注册商: NiceNIC.
为保留原始取证记录,下方的 PhishDestroy AI 详细分析仍使用英文。
PhishDestroy has flagged zerogastrx.trade as an active fake gastritis treatment scam posing as a legitimate medical website. This domain mimics trusted pharmaceutical or health supplement sites to deceive users into purchasing unproven or counterfeit gastritis treatments, potentially leading to financial loss or exposure to harmful substances. The threat is particularly insidious because it exploits health-related fears and urgency, tricking victims into sharing personal and payment details under false pretenses. The domain was registered through NICENIC INTERNATIONAL GROUP CO., LIMITED on March 31, 2026, and resolves to IP address 206.251.50.128. VirusTotal currently shows 3/95 detections, indicating it has not yet been widely recognized as malicious by security vendors, which increases the risk of successful deception. The technical indicators further underscore the domain’s suspicious nature. Despite utilizing a Let’s Encrypt SSL certificate—a tactic often used to appear legitimate—this domain lacks verifiable legitimacy in the health or pharmaceutical sectors. The recent registration date (March 31, 2026) suggests a hastily deployed campaign, as threat actors frequently register new domains to evade detection. Additionally, the absence of detections on VirusTotal, despite its active status and specific malicious intent, highlights the importance of proactive threat intelligence. While blocklist counts are not yet available, the combination of a newly registered domain, a generic registrar, and an unverified SSL certificate should serve as immediate red flags for security-conscious users. If you have visited zerogastrx.trade or interacted with its content, cease all communication and transactions immediately. Do not enter any personal or payment information, as this data may be harvested for fraudulent purposes. Run a full malware scan on your device using reputable antivirus software to detect any potential infections. Report the domain to your email provider and financial institutions to prevent further exploitation. Avoid clicking on any links or downloading attachments from this site in the future. For ongoing protection, consider using browser extensions that block known phishing domains and regularly monitor your financial accounts for unauthorized activity. PhishDestroy advises vigilance and recommends verifying the legitimacy of health-related websites through trusted sources before engaging with their services.
网络安全情报 Registrar context
威胁响应 Pipeline
公共封禁名单状态
已保存的截图
域名情报
技术细节DNS、SSL SAN、时间戳
ICANN OVERSIGHT
认证和 RAA 背景
认证和 RAA 背景
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Latest Classified Outcome 2026-08-14 12:53:33 UTC
所用技术 · 4 identified
Utility-first CSS framework for rapid custom UI development.
High-performance HTTP server and reverse proxy, known for stability and low resource usage.
HTTP Strict Transport Security — forces browsers to use HTTPS connections only.
VirusTotal 分析
证据与外部报告
PD-20260331-1CB7A6 Recipient: abuse@cloudsource.pro 您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。