# PhishDestroy threat dossier — zoom-a.com.cn ================================================================ Fetched: 2026-06-07 00:12:10 UTC Canonical: https://phishdestroy.io/domain/zoom-a.com.cn/ ## VERDICT ---------------------------------------------------------------- TAKEN DOWN (neutralised) Composite threat score: 100/100 (PhishDestroy scoring — see methodology below) ## DETECTION EVIDENCE ---------------------------------------------------------------- VirusTotal: 8/92 security vendors flagged this domain Public blocklists: listed on 3 independent blocklists ## INFRASTRUCTURE ---------------------------------------------------------------- IP address: 38.91.116.179 (US, Los Angeles) ASN: AS9294 GNET INC. Hosting org: Gnet Inc Registrar: Web Commerce Communications Limited Nameservers: a.share-dns.com, a12.share-dns.com, b.share-dns.net, b12.share-dns.net Registered: 2026-05-15 Page title: ZOOM - 官方多人会议软件|官方下载 HTTP response: 200 ## TLS CERTIFICATE ---------------------------------------------------------------- Issuer: Let's Encrypt / R13 Expires: 2026-08-13 Status: INVALID chain Fingerprint: bebae12c9887509982fb995719dace0ccdc4b67749ece8dade94b09fa6968e64 Subject Alternative Names (related infrastructure — often same operator): - www.zoom-a.com.cn ## ABUSE-REPORT HISTORY (evidence of registrar non-response) ---------------------------------------------------------------- Status: CLOSED — no report required. This domain was neutralised before the abuse-report cycle could be dispatched — either the hosting provider / registrar suspended it on their own, the DNS went dead, or the operator abandoned the infrastructure. PhishDestroy keeps the evidence bundle on file for audit but no formal notice was sent. ## TIMELINE ---------------------------------------------------------------- Domain registered: 2026-05-15 (per WHOIS / CT — may reflect a renewal or transfer date, not first-ever registration) First detected: 2026-05-18 14:50:56 UTC (by PhishDestroy tracker) First reported: 2026-05-18 11:51:17 UTC (abuse notice filed) Last verified: 2026-06-07 01:20:28 UTC Neutralised: 2026-06-06 17:30:36 UTC Current status: taken down (registrar suspended or DNS dead) ## EXTERNAL CORROBORATION (third-party evidence) ---------------------------------------------------------------- URLScan.io: https://urlscan.io/result/019e3aea-dd22-750a-8c1d-284309c0f9ea/ URLQuery: https://urlquery.net/report/2abde389-06d4-4a7e-941b-00c108027a7d Wayback Machine: https://web.archive.org/web/*/zoom-a.com.cn crt.sh CT logs: https://crt.sh/?q=%25.zoom-a.com.cn Google transparency: https://transparencyreport.google.com/safe-browsing/search?url=zoom-a.com.cn AlienVault OTX: https://otx.alienvault.com/indicator/domain/zoom-a.com.cn URLhaus: https://urlhaus.abuse.ch/host/zoom-a.com.cn/ ## ANALYST NARRATIVE ---------------------------------------------------------------- [Generated: 2026-05-18 14:51:31 UTC — narrative may predate facts above. Treat fields in TIMELINE / DETECTION EVIDENCE / INFRASTRUCTURE as authoritative if they differ from the prose below.] PhishDestroy identifies zoom-a.com.cn as an active cryptocurrency drainer phishing domain that lures victims into connecting their wallets to a fraudulent interface. The domain mimics legitimate Zoom services in an attempt to harvest private keys and drain funds from unsuspecting users. Technical analysis indicates this site is part of a broader campaign targeting crypto holders through fake login portals and fraudulent Zoom meeting invitations. Users should treat any communication from or about this domain as malicious and avoid interaction entirely. This domain was flagged under seed 2222c3 and exhibits multiple red flags including a Let's Encrypt SSL certificate, zero detections on VirusTotal (0/95), a recent creation date of May 15, 2026, and hosting on IP address 38.91.116.179. The domain is registered through Web Commerce Communications Limited (Webnic), which has been associated with numerous malicious registrations. While currently undetected by antivirus engines, its recent creation and suspicious infrastructure warrant immediate caution. The complete lack of detection combined with active hosting suggests this campaign is in its early deployment phase. If you have visited zoom-a.com.cn or entered any information on the site, disconnect your wallet immediately and revoke any connected permissions. Scan your device for malware using PhishDestroy's threat removal tools and consider rotating all wallet credentials. Do not interact with any further communications from this domain or similar-looking URLs. Report the domain to PhishDestroy and your local cybercrime unit to help disrupt this campaign. Always verify links through PhishDestroy's verification service before clicking, especially those claiming to be from Zoom or other financial services. [Updates since narrative was generated:] - VirusTotal detections: now 8/92 (narrative was written when count was lower) ## EVIDENCE HASHES ---------------------------------------------------------------- PhishDestroy Case ID: PD-20260518-E69A42 TLS cert SHA-256: bebae12c9887509982fb995719dace0ccdc4b67749ece8dade94b09fa6968e64 ## SCORING METHODOLOGY ---------------------------------------------------------------- Composite score is NOT derived from VirusTotal alone. PhishDestroy aggregates: - VirusTotal positive ratio - Public blocklist consensus (MetaMask, ScamSniffer, OpenPhish, PhishTank, URLhaus, CryptoFirewall, SEAL, Polkadot, Enkrypt, Phishunt, DiscordPhishing, PhishingDB) - Cloaking detection (HTTP 666 or rendering delta between bot and real visitor) - DNS-filter consensus (Quad9, CleanBrowsing, NextDNS, AdGuard, Cloudflare, etc.) - AlienVault OTX pulses + Cloudflare Radar + Google Safe Browsing - URLScan / URLQuery verdicts - Brand-impersonation heuristics (DOM analysis of forms, logos, wording) - Known phishing-kit fingerprinting (favicon hash, JS obfuscation signatures) - Wallet-drainer family classification (Angel, MS, Rainbow, Pink, Inferno, ...) - Free-TLS vs paid-cert ratio (throwaway infrastructure signal) - Registrar/hosting abuse history (this registrar's track record) - Human researcher sign-off (volunteer takedown team) A domain present in our database is ALREADY flagged. A low VT count by itself does NOT mean the domain is safe — new scam domains routinely show 0/95 VT for their first 7–30 days while actively draining wallets. Always cross-reference the composite score and the individual indicators above, not just VT. ## CORRECTIONS / APPEALS ---------------------------------------------------------------- Full HTML report: https://phishdestroy.io/domain/zoom-a.com.cn/ JSON API: https://api.destroy.tools/v1/check?domain=zoom-a.com.cn Appeal a flag: https://phishdestroy.io/appeals/ (responded to within 48 hours, FP rate <0.01%) Submit a report: https://t.me/PhishDestroy_bot About PhishDestroy: volunteer-driven open-source threat-intelligence platform. Tracked: 157,745 domains (42,536 alive under monitoring, 114,256 confirmed takedowns/dead). Site: https://phishdestroy.io