w41zoom[.]us
“Zoom Meeting”
Résumé des preuves
Analysis of the domain w41zoom.us, which was taken offline as of the report date, indicates a confirmed brand‑impersonation campaign targeting Zoom users. The domain was registered on 20 October 2025 through NameSilo, LLC and uses the generic nameservers ns1045.ui-dns.biz, ns1045.ui-dns.com, ns1045.ui-dns.de and ns1045.ui-dns.org. DNS resolution points to IP 74.208.236.228, an address hosted in the United States under AS8560 (IONOS SE). No TLS certificate is presented, meaning the site operated without HTTPS protection.
The page title returned by the server was “Zoom Meeting,” directly referencing the Zoom brand, and the scam type is listed as “Brand Impersonation.” The domain appears on a single security blocklist and has been blocked by the PhishDestroy service. Reputation scoring from Gridinsoft assigns a trust score of 0 / 100, and nine of ninety‑five VirusTotal scanners flagged the domain as malicious. These indicators collectively suggest a high‑confidence malicious intent despite the current offline status. Uncertainties remain regarding the exact payload delivered, any credential‑harvesting mechanisms, and whether additional infrastructure (e.g., command‑and‑control servers) is associated with the same IP range.
Defenders should add w41zoom.us to internal blocklists, monitor for any future re‑registration of the domain or similar variants, and ensure that web filtering solutions incorporate the observed blocklist and detection signatures. Network traffic to 74.208.236.228 should be inspected for anomalous HTTP requests, and any user reports of unexpected “Zoom Meeting” redirects should be triaged promptly. Continuous review of the associated nameservers and the hosting ASN is recommended to detect potential reuse by other malicious actors.
Data Coverage
Renseignements sur la sécurité réseau
Processus de réponse aux menaces Pipeline
Couverture des listes de blocage
10 sources externes surveillées · instantané du 12/08/2026
10 sources externes surveillées Aucune correspondance
Chronologie de détection
-
Cloudflare Radar
Analyse Cloudflare Radar enregistrée · Ouvrir l’analyse
Analyse VirusTotal
Ce site vous a-t-il affecté ?
Si vous avez saisi des informations d'identification de compte, des informations personnelles ou de paiement, ou téléchargé un fichier à partir de ce domaine, agissez immédiatement. Vous trouverez ci-dessous des ressources pour vous aider à signaler l'incident et à vous protéger.
Signalez-le à vos autorités locales
Sélectionnez votre pays pour obtenir contacts officiels en matière de cybercriminalité ou créer un projet de plainte →.
Vérifier n'importe quel domaine
Analyse des menaces à l'aide de listes de blocage stockées, de WHOIS, de DNS et de preuves d'analyse publique
Scanner maintenantSignaler une tentative d'hameçonnage
Signalez les domaines suspects à notre base de données des menaces — protégez la communauté
SignalerFlux d'alertes en temps réel
Rapports de phishing récents et changements de disponibilité observés
SurveillerRestez informés, restez en sécurité
Surveillez les menaces en temps réel ou signalez cette alerte si vous pensez qu'il s'agit d'un faux positif