usweb[.]02room[.]us
Zusammenfassung der Beweislage
This domain, usweb.02room.us, is identified as a credential harvesting phishing site designed to deceive users into submitting sensitive login credentials through fraudulent web portals. Analysis indicates the infrastructure is tailored to mimic legitimate authentication pages, likely targeting corporate, financial, or personal accounts. The domain employs social engineering tactics to exploit user trust, redirecting victims to cloned interfaces where credentials are captured in real time for unauthorized access or financial fraud. Infrastructure analysis reveals concrete indicators of malicious intent. The domain was registered on June 01, 2026, an unusually recent creation date that aligns with common phishing lifecycle patterns. It resolves to the IP address 172.86.91.195, which has been associated with prior phishing campaigns. Security vendors on VirusTotal flagged usweb.02room.us with a detection ratio of 16/95, confirming its classification as malicious by multiple threat intelligence sources. Additionally, the domain appears on one security blocklist and has since been taken offline, though residual risk remains for users who may have interacted with it before deactivation. Users who visited usweb.02room.us or entered credentials on any page hosted under this domain should take immediate corrective action. First, revoke any submitted passwords and enable multi-factor authentication on all associated accounts to prevent unauthorized access. Second, monitor linked accounts for suspicious activity, such as unrecognized logins or transactions. Third, scan local devices for malware using updated security tools, as phishing sites may deploy secondary payloads. If corporate credentials were exposed, report the incident to internal security teams to initiate containment protocols. Given the elevated risk level, affected users should assume compromise and act accordingly to mitigate potential damage.
Data Coverage
Pipeline zur Reaktion auf Sicherheitsbedrohungen
Blocklistenabdeckung
10 überwachte externe Feeds · gespeicherter Stand 11.08.2026
Domain-Intelligenz
Technische DetailsDNS, TLS-Namen und Zeitstempel
VirusTotal-Analyse
Wurden Sie von dieser Website betroffen?
Wenn Sie Kontoanmeldeinformationen, persönliche oder Zahlungsinformationen eingegeben oder eine Datei von dieser Domain heruntergeladen haben, ergreifen Sie sofort Maßnahmen. Nachfolgend finden Sie Ressourcen, die Ihnen helfen, den Vorfall zu melden und sich zu schützen.
Melden Sie sich bei Ihren örtlichen Behörden
Wählen Sie Ihr Land aus, um Offizielle Kontakte im Bereich Cyberkriminalität oder einen Beschwerdeentwurf erstellen → zu erhalten.
Jede beliebige Domain prüfen
Bedrohungsanalyse anhand gespeicherter Blocklisten, WHOIS, DNS und öffentlicher Scan-Beweise
Jetzt scannenPhishing melden
Melden Sie verdächtige Domains an unsere Bedrohungsdatenbank – schützen Sie die Community
MeldenEchtzeit-Bedrohungsfeed
Aktuelle Phishing-Meldungen und beobachtete Verfügbarkeitsänderungen
ÜberwachenBleiben Sie auf dem Laufenden, bleiben Sie sicher
Beobachten Sie aktuelle Bedrohungen oder legen Sie Widerspruch gegen diesen Eintrag ein, wenn Sie der Meinung sind, dass es sich um einen Fehlalarm handelt