us05webs[.]com
us05webs.com की फ़िशिंग और सुरक्षा जाँच
“One platform to connect | Zoom”
us05webs.com — सामग्री अनुपलब्ध (HTTP 502). ब्रांड प्रतिरूपण: Across. साक्ष्य सारांश: VirusTotal 4/93 (Fortinet, Gridinsoft, PhishFort, SOCRadar); Spamhaus DBL_PHISH; 2 external blocklist matches (MetaMask, SEAL); PhishDestroy score 66/100. रजिस्ट्रार: NiceNIC.
मूल फॉरेंसिक रिकॉर्ड सुरक्षित रखने के लिए नीचे का विस्तृत PhishDestroy AI विश्लेषण अंग्रेज़ी में रखा गया है।
us05webs.com was observed on July 25, 2026 delivering a generic phishing campaign that mimics Zoom, as indicated by the page title “One platform to connect | Zoom”. The domain was registered on 21 February 2026 through NiceNIC International Group Co., Limited and is hosted behind Cloudflare infrastructure (ASN 13335). DNS resolution points to IP address 188.114.97.3, which is geolocated to the United States and is associated with Cloudflare’s edge network. No SSL certificate was presented during the scan, meaning the site served over plain HTTP.
VirusTotal analysis recorded four detections out of ninety‑three security vendors, confirming that multiple scanners have identified malicious behavior. The domain appears on three public blocklists and is explicitly blocked by PhishDestroy, MetaMask, and SEAL, reinforcing its classification as a phishing vector. Nameserver configuration uses Cloudflare’s authoritative servers kallie.ns.cloudflare.com and steven.ns.cloudflare.com, a common pattern for fast‑flux or abuse‑friendly domains. The site was taken offline at the time of reporting, and no further HTTP response details are available.
While the page title suggests an attempt to impersonate Zoom, the actual content of the landing page has not been captured, leaving the precise credential‑harvesting technique uncertain. Defenders should continue to block the domain at perimeter defenses, monitor DNS queries for the associated IP and nameservers, and add the domain to internal threat‑intel feeds. Additional harvesting of payloads or redirects should be pursued if the site resurfaces, and any credentials submitted to the URL should be treated as compromised. Ongoing observation of the hosting provider and registrar may reveal further related infrastructure.
नेटवर्क सुरक्षा इंटेलिजेंस Registrar context
धमकी प्रतिक्रिया पाइपलाइन
सार्वजनिक ब्लॉकलिस्ट स्थिति
सहेजा गया कैप्चर
डोमेन इंटेलिजेंस
तकनीकी विवरणडीएनएस, एसएसएल एसएएन, टाइमस्टैम्प
ICANN OVERSIGHT
प्रत्यायन और आरएए संदर्भ
प्रत्यायन और आरएए संदर्भ
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Latest Classified Outcome 2026-08-08 04:29:00 UTC
वायरसटोटल विश्लेषण
संग्रहीत साक्ष्य
साक्ष्य और बाहरी रिपोर्टें
PD-20260215-240EB0 Recipient: abuse@nicenic.net, abuse@verisign-grs.com, compliance@icann.org क्या आप इस साइट से प्रभावित हुए?
यदि आपने खाता क्रेडेंशियल, व्यक्तिगत या भुगतान जानकारी दर्ज की है, या इस डोमेन से कोई फ़ाइल डाउनलोड की है, तो तुरंत कार्रवाई करें। घटना की रिपोर्ट करने और अपनी सुरक्षा करने में आपकी सहायता के लिए नीचे संसाधन दिए गए हैं।
अपने स्थानीय अधिकारियों को रिपोर्ट करें
आधिकारिक साइबर अपराध संपर्क, या एक शिकायत ड्राफ्ट बनाएं → प्राप्त करने के लिए अपना देश चुनें।
किसी भी डोमेन की जाँच करें
संग्रहीत ब्लॉकलिस्ट, WHOIS, DNS और सार्वजनिक स्कैन साक्ष्य का उपयोग करके खतरे का विश्लेषण
अभी स्कैन करेंफ़िशिंग की रिपोर्ट करें
संदिग्ध डोमेन हमारे थ्रेट डेटाबेस में जमा करें — समुदाय की सुरक्षा करें
रिपोर्ट करेंसीधा खतरा फीड
हाल की फ़िशिंग रिपोर्टें और उपलब्धता में परिवर्तन देखे गए
निगरानी करेंजानकारी में रहें, सुरक्षित रहें
लाइव खतरों की निगरानी करें या यदि आपको लगता है कि यह एक गलत सकारात्मक है तो इस लिस्टिंग को चुनौती दें।