zoommeetingsinvitees[.]com
“Download Zoom”
ملخص الأدلة
The domain zoommeetingsinvitees.com was registered on February 21 2026 through NameSilo, LLC. DNS resolution points to the IPv4 address 89.163.155.33, which is announced by AS24961 (WIIT AG) and geolocated to Germany. The authoritative name servers are ns7.privatedns.vip and ns8.privatedns.vip, both of which are commonly used by malicious infrastructure. No TLS certificate is presented, indicating the site is served only over HTTP, which further reduces trust. The HTTP response currently returns an offline status, confirming that the site is not actively hosting content at the time of analysis. The page title reported by passive monitoring reads “Download Zoom,” and the threat classification is listed as brand impersonation targeting the Zoom brand.
This aligns with two AlienVault OTX pulses that reference the domain, indicating that it has been observed in prior threat intel. Gridinsoft assigns a trust score of 0 out of 100, and the domain appears on three known security blocklists. Additional blocklist entries from PhishDestroy, MetaMask, and SEAL confirm that the domain is being actively blocked by multiple protective services. VirusTotal analysis shows that 17 out of 93 scanning engines flagged the domain as malicious, reinforcing the suspicion of fraudulent activity.
The combination of a brand‑specific page title, low trust score, multiple blocklist listings, and detections by reputable scanners suggests a high probability that the domain was used to lure victims into downloading counterfeit Zoom software or to harvest credentials. Defenders should continue to block zoommeetingsinvitees.com at network perimeters, update URL filtering policies, and monitor for any resurgence of activity from the associated IP address or name servers. Because the site is currently offline, any future re‑activation would likely repeat the same impersonation tactics, so continuous vigilance is advised.
لقطة الأدلة المرسلة
- أُرسل
- سجلات الدفتر
- 1
- معرّف القضية
PD-20260130-B24CD6- عنوان الصفحة الملتقطة
- Download Zoom
- ملف PDF
- دليل PDF
الأساس القانوني
النص الكامل للدليل
Acceptable Use Policy: The domain zoommeetingsinvitees.com is engaged in phishing activities, which are explicitly prohibited under your AUP. This domain is designed to deceive users into providing sensitive information under the guise of legitimate Zoom meeting invitations.
Terms of Service: The continued operation of this domain constitutes a violation of your TOS, which reserves the right to suspend or terminate services for any activities involving fraud or deception.
Applicable Laws (US):
Computer Fraud and Abuse Act (18 U.S.C. § 1030): This federal law prohibits unauthorized access to computers and the fraudulent use of information obtained from such access, which applies to phishing schemes.
Wire Fraud (18 U.S.C. § 1343): This statute criminalizes schemes to defraud individuals or entities using electronic communications, including phishing activities that aim to mislead victims for financial gain.
CAN-SPAM Act (15 U.S.C. § 7701): This law regulates commercial email and prohibits deceptive practices in electronic communications, which includes phishing emails.
Regulatory Note: Failure to take prompt action against this domain may expose your organization to liability under applicable laws and regulations. Continued non-compliance could result in regulatory scrutiny and potential penalties.
Data Coverage
استخبارات أمن الشبكات
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| Hagezi Threat Feed | sampaworks.info |
malicious | Sinkholed |
| DNS4EU | sampaworks.info |
malicious | Sinkholed |
مسار الاستجابة للتهديدات Pipeline
تغطية قوائم الحظر
١٠ مصادر خارجية مراقبة · لقطة محفوظة 13/08/2026
المخطط الزمني للاكتشاف
-
Cloudflare Radar
تم حفظ فحص Cloudflare Radar · فتح الفحص
لقطة محفوظة
معلومات النطاق
التفاصيل التقنيةDNS وأسماء TLS والطوابع الزمنية
ICANN OVERSIGHT
الاعتماد وسياق RAA
الاعتماد وسياق RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
تحليل VirusTotal
هل تأثرت بهذا الموقع؟
إذا أدخلت بيانات اعتماد الحساب أو المعلومات الشخصية أو معلومات الدفع أو قمت بتنزيل ملف من هذا النطاق، فاتخذ إجراءً فوريًا. فيما يلي موارد لمساعدتك في الإبلاغ عن الحادث وحماية نفسك.
أبلغ السلطات المحلية
حدد بلدك للحصول على الاتصالات الرسمية المتعلقة بالجرائم الإلكترونية أو إنشاء مسودة شكوى →.
تحقق من أي نطاق
تحليل التهديدات باستخدام قائمة الحظر المخزنة، وWHOIS، وDNS، وأدلة الفحص العامة
امسح الآنالإبلاغ عن محاولة تصيد احتيالي
أرسل النطاقات المشبوهة إلى قاعدة بيانات التهديدات الخاصة بنا — ساهم في حماية المجتمع
إبلاغتحديثات فورية حول التهديدات
تقارير التصيد الاحتيالي الأخيرة وتغييرات التوفر الملحوظة
مراقبةابقَ على اطلاع، وابقَ آمنًا
راقب التهديدات في الوقت الفعلي أو اعترض على هذا الإدراج إذا كنت تعتقد أنه إنذار كاذب