Skip to security report
⚠️
This domain has been flagged as malicious
Security engines reporting a detection: 4. Public blocklists reporting a match: 2. Exercise extreme caution — do not enter credentials or personal information.
Domain security and threat intelligence

1z0[.]us

Phishing and security check for 1z0.us

“YouTube”

Threat verdict Critical 93/100 evidence score
Availability Cloaked · reachable Reachability observed through cloaking checks
Risk signals
VirusTotal detections: 4/91 Spamhaus DBL: DBL_SPAM Stored blocklist matches: 2 Last known active
4/91 VT Jun 18, 2026 2 Blocklists Cloaking CDN

Evidence Facts

Ref 78FA789E 93/100 CRITICAL

PhishDestroy first observed 1z0.us on Jun 18, 2026. The captured page title is “YouTube”. Evidence score: 93/100 (critical).

4 independent sources recorded positive findings: VirusTotal, MetaMask, SEAL, and Spamhaus DBL. VirusTotal recorded 4 detections among 91 engines: alphaMountain.ai, ESET, Fortinet, Gridinsoft on Jul 14, 2026 at 19:40 UTC. MetaMask and SEAL listed the hostname in the separate external-blocklist snapshot on Aug 9, 2026 at 10:20 UTC. Spamhaus DBL: DBL_SPAM on Jul 17, 2026 at 22:30 UTC.

Cloaking was recorded with HTTP 200 on Aug 9, 2026 at 10:04 UTC. The cloaking probe recorded bot redirect safe conditional delivery at 4/100 on Aug 9, 2026 at 10:04 UTC: alive_content: raw=ok; http=200; via=https_proxy; server=nginx/1.18.0 (Ubuntu). The recorded creation date for the domain is Jun 17, 2026. At collection time, the hostname resolved to 37.77.150.237 on AS198953 (Proton66 OOO).

VirusTotal
VirusTotal
4 det.
TLS Certificate
Let's Encrypt / YR1
Age
2 mo New
Observed status
Cloaked · reachable 200
PhishDestroy
DestroyList
Listed
Data coverage12 recorded checks
VirusTotal 4 / 91 URLQuery not checked PhishStats not checked OTX no community references CF Radar scan completed URLScan capture not submitted URLScan verdict verdict unavailable DNS blocks not checked TLS valid certificate, 34d WHOIS 2 mo old Screenshot not captured Redirect chain not probed

Threat Response Pipeline

Discovery
Checks
Reports
Availability
8/10

Public Blocklist Status

Domain Intelligence

Domain
Server / ASN cloudflare · AS198953 Proton66 OOO
IP Context Cloudflare shared edge origin IP hidden Edge-IP reputation is not attributed to this domain.
IP Address 37.77.150.237 CDN
GeoRU Zelenograd, RU
NetworkAS198953 · LLC Baxet
The origin IP is hidden behind a CDN proxy. Reverse-IP results for the edge address contain unrelated tenants; finding the origin requires passive DNS or certificate-transparency data.
RegistrationCreated Jun 17, 2026 (53d · New)
Cloaking Cloaking Detected Bot redirect safe · score 4/6
alive_content: raw=ok; http=200; via=https_proxy; server=nginx/1.18.0 (Ubuntu)
server: nginx/1.18.0 (Ubuntu) title: Your all-in-one social tool - Replace me
checked Aug 9, 2026
HTTP Status200
Technical detailsDNS, SSL SANs, timestamps
First DetectedJun 18, 2026
TLS Fingerprint
TLS Observationvalid from Jun 15, 2026scanned Jun 17, 2026
Technologies · 3 identified
YouTube
Video players

YouTube is a video sharing service where users can create their own profile, upload videos, watch, like and comment on other videos.

www.youtube.com 100% confidence
HSTS
Security

HTTP Strict Transport Security (HSTS) informs browsers that the site should only be accessed using HTTPS.

www.rfc-editor.org 100% confidence
HTTP/3
Miscellaneous

HTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.

httpwg.org 100% confidence
Detected via Cloudflare Radar · Wappalyzer engine
Report This Domain Submit evidence & help protect others

VirusTotal Analysis

4 / 91 security vendors flagged this domain
View on VT
Last analyzed
alphaMountain.ai
ESET
Fortinet
Gridinsoft
Site Configuration Analysis
Stored observations are retained with their original collection time.
robots.txt Present · HTTP 200
Valid robots.txt; no Disallow/Allow paths were extracted.
Evidence & External ReportsIndependent lookups and source reports
Victim safety and official reportingImmediate actions and verified reporting channels
If credentials were compromised, report immediately. Do not engage with recovery scammers.

If credentials, payment data, or files were exposed, report the incident immediately. Change affected passwords, revoke active sessions, and scan the device.

Europol
Find the official reporting channel for your EU country
National police directory
Beware of recovery scammers! Recovery scammers may pose as investigators, lawyers, or tracing services. Do not pay upfront fees or disclose credentials. Learn more about recovery fraud →

Report to Your Local Authorities

Select your country to get official cybercrime contacts, or create a complaint draft →.

97-country directory
Template-based draft • optional AI wording assistance requires separate consent Review and submit it yourself
Embed This ReportRead-only HTML widget
HTML · IFRAME

Embed This Report

Share this threat intelligence on your website or blog

embed.html
<iframe
  src="https://phishdestroy.io/embed/domain/1z0.us"
  title="PhishDestroy threat report for 1z0.us"
  width="100%" height="320"
  loading="lazy"
  referrerpolicy="no-referrer"
  sandbox="allow-same-origin allow-popups allow-popups-to-escape-sandbox"
  style="border:0;border-radius:12px;max-width:100%"
></iframe>