gov-db635f70-zlimbra-4528-48ac-6460e3[.]netlify[.]app
“Zimbra Web Client Sign In”
gov-db635f70-zlimbra-4528-48ac-6460e3.netlify.app — सामग्री अनुपलब्ध. घोटाले का प्रकार: Credential Phishing. साक्ष्य सारांश: VirusTotal 9/93 (ADMINUSLabs, alphaMountain.ai, BitDefender, CyRadar, G-Data); PhishDestroy score 77/100. रजिस्ट्रार: Name.com.
मूल फॉरेंसिक रिकॉर्ड सुरक्षित रखने के लिए नीचे का विस्तृत PhishDestroy AI विश्लेषण अंग्रेज़ी में रखा गया है।
Analysis of gov-db635f70-zlimbra-4528-48ac-6460e3.netlify.app shows a recently registered Netlify‑hosted site that has been taken offline. The domain was created on February 23, 2026 and is registered through Name.com, Inc. Infrastructure inspection reveals the site resolved to the Amazon Web Services address 54.253.94.210, which is assigned to AS16509 in Germany. The TLS certificate presented is a DigiCert Global G2 RSA SHA256 2020 CA1 chain, issued by DigiCert Inc, and the site advertised HSTS support. The page title captured during the brief online window was "Zimbra Web Client Sign In," matching the declared scam type of credential phishing targeting Zimbra users.
HTTP response returned a 404 status code, indicating the content was no longer served at the time of checking. Threat intelligence feeds list the domain on a single security blocklist and note that PhishDestroy has actively blocked it. VirusTotal scans recorded nine of ninety‑three antivirus engines flagging the domain as malicious, reinforcing the phishing assessment.
While the exact phishing landing page cannot be examined because the site is offline, the combination of a deceptive Zimbra‑related title, credential‑phishing classification, reputable SSL certificate, and corroborating blocklist entries provide strong evidence of malicious intent. Defenders should continue to block the domain at network perimeter, monitor for any re‑hosting attempts on Netlify or other cloud providers, and update endpoint protection signatures to include the observed VirusTotal detections. Further investigation may focus on any associated URLs or email campaigns that reference this domain to assess potential victim exposure.
धमकी प्रतिक्रिया पाइपलाइन
सार्वजनिक ब्लॉकलिस्ट स्थिति
तकनीकें · 3 identified
Netlify providers hosting and server-less backend services for web applications and static websites.
www.netlify.com 100% विश्वासHTTP Strict Transport Security (HSTS) informs browsers that the site should only be accessed using HTTPS.
www.rfc-editor.org 100% विश्वासवायरसटोटल विश्लेषण
संग्रहीत साक्ष्य
साक्ष्य और बाहरी रिपोर्टें
क्या आप इस साइट से प्रभावित हुए?
यदि आपने खाता क्रेडेंशियल, व्यक्तिगत या भुगतान जानकारी दर्ज की है, या इस डोमेन से कोई फ़ाइल डाउनलोड की है, तो तुरंत कार्रवाई करें। घटना की रिपोर्ट करने और अपनी सुरक्षा करने में आपकी सहायता के लिए नीचे संसाधन दिए गए हैं।
अपने स्थानीय अधिकारियों को रिपोर्ट करें
आधिकारिक साइबर अपराध संपर्क, या एक शिकायत ड्राफ्ट बनाएं → प्राप्त करने के लिए अपना देश चुनें।
किसी भी डोमेन की जाँच करें
संग्रहीत ब्लॉकलिस्ट, WHOIS, DNS और सार्वजनिक स्कैन साक्ष्य का उपयोग करके खतरे का विश्लेषण
अभी स्कैन करेंफ़िशिंग की रिपोर्ट करें
संदिग्ध डोमेन हमारे थ्रेट डेटाबेस में जमा करें — समुदाय की सुरक्षा करें
रिपोर्ट करेंसीधा खतरा फीड
हाल की फ़िशिंग रिपोर्टें और उपलब्धता में परिवर्तन देखे गए
निगरानी करेंजानकारी में रहें, सुरक्षित रहें
लाइव खतरों की निगरानी करें या यदि आपको लगता है कि यह एक गलत सकारात्मक है तो इस लिस्टिंग को चुनौती दें।