us06webs[.]us
Análisis de phishing y seguridad de us06webs.us
“One platform to connect | Zoom”
us06webs.us — Contenido no disponible (HTTP 502). Suplantación de marca: Across; Tipo de estafa: Brand Impersonation. Resumen de las pruebas: VirusTotal 4/93 (alphaMountain.ai, Forcepoint ThreatSeeker, PhishFort, SOCRadar); PhishDestroy score 65/100. Registrador: CNOBIN INFORMATION TEC….
El análisis detallado de PhishDestroy AI se mantiene en inglés para conservar el registro forense original.
The domain us06webs.us was registered on 21 February 2026 via CNOBIN INFORMATION TECHNOLOGY LIMITED and points to the IPv6 address 2407:30c0:183::aa72:4e50, which is announced by AS13335 Cloudflare, Inc. in the United States. The domain is configured to use Cloudflare’s authoritative nameservers justin.ns.cloudflare.com and margot.ns.cloudflare.com, but no TLS certificate is present, indicating the site was served without HTTPS. As of the report date the host is taken offline, and there is no active HTTP response to probe further. Threat intelligence flags the site as a brand‑impersonation campaign; the page title returned from the server is “One platform to connect | Zoom”, suggesting an attempt to lure victims under the Zoom brand.
VirusTotal scans show four of ninety‑three security vendors flag the domain as malicious, and the domain appears on three public blocklists. Additional protective products have listed the domain as blocked, including PhishDestroy, MetaMask, and SEAL. Gridinsoft assigns a trust score of zero out of one hundred, reinforcing the malicious assessment. The available data confirms the infrastructure is hosted behind Cloudflare, a common choice for fast‑flux or anonymised phishing infrastructure, and the lack of TLS further reduces credibility.
Uncertainty remains regarding the exact phishing kit or payload because no page content has been captured and the site is offline. Defenders should add us06webs.us to blocklists at the network perimeter, update DNS sinkhole entries, and monitor for any related sub‑domains or new domains registered by the same registrar. Continuous re‑scanning with VirusTotal and other multi‑engine platforms is advised to capture any future changes, and any traffic to the associated IPv6 address should be logged and investigated for potential credential harvesting attempts.
Proceso de respuesta ante amenazas Pipeline
Estado de la lista de bloqueados pública
Análisis de VirusTotal
Datos y informes externos
¿Te ha afectado esta página web?
Si ingresó credenciales de cuenta, información personal o de pago, o descargó un archivo de este dominio, tome medidas inmediatas. A continuación encontrará recursos que le ayudarán a informar el incidente y protegerse.
Informa a las autoridades locales
Seleccione su país para obtener contactos oficiales de cibercrimen o crear un borrador de queja →.
Comprobar cualquier dominio
Análisis de amenazas utilizando listas de bloqueo almacenadas, WHOIS, DNS y evidencia de escaneo público
Escanear ahoraDenunciar un intento de phishing
Envía los dominios sospechosos a nuestra base de datos de amenazas: protege a la comunidad
DenunciarFlujo de amenazas en tiempo real
Informes de phishing recientes y cambios de disponibilidad observados
MonitorizarMantente informado, mantente a salvo
Supervisa las amenazas en tiempo real o impugna esta entrada si crees que se trata de un falso positivo.