MALICIOUS — CRITICAL
Phishing- und Sicherheitsprüfung für us81webzoom.us
us81webzoom[.]
The domain us81webzoom.us was registered through Dynadot Inc on February 21, 2026 and is currently resolving to the IP address 87.236.16.18, which belongs to Beget LLC in Russia (AS198610).
- VirusTotal
- 11/93
- Blocklists
- No stored match
- Verfügbarkeit
- Erreichbar · Zugang eingeschränkt · HTTP 403
Do not enter credentials, seed phrases, payment details, or personal information on this domain.
Jump to section
us81webzoom.us — Erreichbar · Zugang eingeschränkt (HTTP 403). Markenidentität: Zoom; Betrugstyp: Account Takeover. Zusammenfassung der Beweislage: VirusTotal 11/93 (alphaMountain.ai, BitDefender, CRDF, CyRadar, ESTsecurity); CF Radar malicious; PhishDestroy score 83/100. Registrar: Dynadot.
Die ausführliche Analyse von PhishDestroy AI bleibt auf Englisch, damit der ursprüngliche forensische Bericht unverändert bleibt.
Evidence Analysis
The domain us81webzoom.us was registered through Dynadot Inc on February 21, 2026 and is currently resolving to the IP address 87.236.16.18, which belongs to Beget LLC in Russia (AS198610). The hosting environment is fronted by Cloudflare and serves content over Nginx, while the page includes client‑side libraries such as Lodash, jQuery (via CDN), FancyBox and cdnjs. An SSL certificate issued by Let’s Encrypt (R13) is present, indicating the site is reachable via HTTPS. DNS is managed by four Beget name servers (ns1.beget.com, ns2.beget.com, ns1.beget.pro, ns2.beget.pro).
HTTP requests return a 403 status, suggesting access restrictions or a deliberately hidden landing page. The page title returned by the server reads “The new site has been successfully created and is ready to work,” which provides no direct indication of the targeted brand or service. Threat intelligence classifies the activity as an account‑takeover scam, and the site is listed on at least one security blocklist. It has been blocked by PhishDestroy and receives a Gridinsoft trust score of 0 / 100, reflecting a very low reputation.
VirusTotal analysis shows that 11 of 93 scanning engines flag the domain as malicious, reinforcing the suspicion of abuse. Defenders should treat the domain as high‑risk: block DNS resolution, enforce URL filtering, and monitor outbound connections to the associated IP. Additional investigation should focus on retrieving the actual page content, identifying any credential‑harvesting forms, and correlating traffic logs for signs of credential submission. Until further evidence is gathered, the domain should be considered an active malicious infrastructure used for account‑takeover campaigns.
Stored source results
Recorded verdicts and infrastructure observations for this domain.
Datenabdeckung12 recorded checks
Erkenntnisse zur Netzwerksicherheit
Pipeline zur Reaktion auf Sicherheitsbedrohungen
Status der öffentlichen Sperrliste
Technologien · 7 identified
Nginx is a web server that can also be used as a reverse proxy, load balancer, mail proxy and HTTP cache.
nginx.org 100 % KonfidenzCloudflare is a web-infrastructure and website-security company, providing content-delivery-network services, DDoS mitigation, Internet security, and distributed domain-name-server services.
www.cloudflare.com 100 % KonfidenzLodash is a JavaScript library which provides utility functions for common programming tasks using the functional programming paradigm.
www.lodash.com 100 % KonfidenzjQuery CDN is a way to include jQuery in your website without actually downloading and keeping it your website's folder.
code.jquery.com 100 % KonfidenzjQuery is a JavaScript library which is a free, open-source software designed to simplify HTML DOM tree traversal and manipulation, as well as event handling, CSS animation, and Ajax.
jquery.com 100 % KonfidenzFancyBox is a tool for displaying images, html content and multi-media in a Mac-style 'lightbox' that floats overtop of web page.
fancyapps.com 100 % KonfidenzVirusTotal-Analyse
Website-Performanceanalyse
Google PageSpeed Insights — mobile performance audit of us81webzoom.us · checked Mar 2, 2026
Nachweise und externe BerichteIndependent lookups and source reports
Victim safety and official reportingImmediate actions and verified reporting channels
Wenn Sie Kontoanmeldeinformationen, persönliche oder Zahlungsinformationen eingegeben oder eine Datei von dieser Domain heruntergeladen haben, ergreifen Sie sofort Maßnahmen. Nachfolgend finden Sie Ressourcen, die Ihnen helfen, den Vorfall zu melden und sich zu schützen.
Melden Sie sich bei Ihren örtlichen Behörden
Wählen Sie Ihr Land aus, um Offizielle Kontakte im Bereich Cyberkriminalität oder einen Beschwerdeentwurf erstellen → zu erhalten.