us06webs[.]com
us06webs.com की फ़िशिंग और सुरक्षा जाँच
“Join from Zoom Workplace app - Zoom”
us06webs.com — सामग्री अनुपलब्ध (HTTP 502). ब्रांड प्रतिरूपण: ["zoom"]. साक्ष्य सारांश: VirusTotal 4 detections (engine total unavailable) (alphaMountain.ai, Fortinet, Gridinsoft, PhishFort); Spamhaus DBL_PHISH; 2 external blocklist matches (MetaMask, SEAL); PhishDestroy score 66/100. रजिस्ट्रार: NiceNIC.
मूल फॉरेंसिक रिकॉर्ड सुरक्षित रखने के लिए नीचे का विस्तृत PhishDestroy AI विश्लेषण अंग्रेज़ी में रखा गया है।
The domain us06webs.com was registered on February 21, 2026 through NiceNIC International Group Co., Limited and is currently listed as offline. DNS resolution points to the IP address 172.67.178.197, which belongs to AS13335 Cloudflare, Inc. and is geolocated in the United States. The authoritative nameservers are kallie.ns.cloudflare.com and steven.ns.cloudflare.com, indicating that the site was hosted behind Cloudflare’s reverse‑proxy service. No SSL/TLS certificate was presented for the host, meaning the site operated without HTTPS encryption.
The only visible page element captured is the title "Join from Zoom Workplace app - Zoom," suggesting the site was designed to lure victims into a Zoom‑related credential‑harvesting flow. VirusTotal scans show that four of ninety‑five security vendors flagged the domain, and three independent blocklists (PhishDestroy, MetaMask, SEAL) have already added it to their deny lists. The domain appears on three additional security blocklists, reinforcing its malicious reputation.
While the exact page content and any payload used have not been disclosed, the combination of a targeted Zoom page title, lack of HTTPS, Cloudflare hosting, and multiple vendor detections strongly indicates a phishing operation aimed at compromising Zoom Workplace credentials. Defenders should continue to block the domain at perimeter and DNS layers, monitor for any resurrection of the host, and consider adding the IP address to threat‑intel feeds. Additional investigation of any associated subdomains or traffic patterns is advised to uncover any broader campaign infrastructure.
नेटवर्क सुरक्षा इंटेलिजेंस Registrar context
धमकी प्रतिक्रिया पाइपलाइन
सार्वजनिक ब्लॉकलिस्ट स्थिति
सहेजा गया कैप्चर
डोमेन इंटेलिजेंस
तकनीकी विवरणडीएनएस, एसएसएल एसएएन, टाइमस्टैम्प
ICANN OVERSIGHT
प्रत्यायन और आरएए संदर्भ
प्रत्यायन और आरएए संदर्भ
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Latest Classified Outcome 2026-08-08 04:29:01 UTC
वायरसटोटल विश्लेषण
संग्रहीत साक्ष्य
साक्ष्य और बाहरी रिपोर्टें
PD-20260215-1E7036 Recipient: abuse@nicenic.net, abuse@verisign-grs.com, compliance@icann.org क्या आप इस साइट से प्रभावित हुए?
यदि आपने खाता क्रेडेंशियल, व्यक्तिगत या भुगतान जानकारी दर्ज की है, या इस डोमेन से कोई फ़ाइल डाउनलोड की है, तो तुरंत कार्रवाई करें। घटना की रिपोर्ट करने और अपनी सुरक्षा करने में आपकी सहायता के लिए नीचे संसाधन दिए गए हैं।
अपने स्थानीय अधिकारियों को रिपोर्ट करें
आधिकारिक साइबर अपराध संपर्क, या एक शिकायत ड्राफ्ट बनाएं → प्राप्त करने के लिए अपना देश चुनें।
किसी भी डोमेन की जाँच करें
संग्रहीत ब्लॉकलिस्ट, WHOIS, DNS और सार्वजनिक स्कैन साक्ष्य का उपयोग करके खतरे का विश्लेषण
अभी स्कैन करेंफ़िशिंग की रिपोर्ट करें
संदिग्ध डोमेन हमारे थ्रेट डेटाबेस में जमा करें — समुदाय की सुरक्षा करें
रिपोर्ट करेंसीधा खतरा फीड
हाल की फ़िशिंग रिपोर्टें और उपलब्धता में परिवर्तन देखे गए
निगरानी करेंजानकारी में रहें, सुरक्षित रहें
लाइव खतरों की निगरानी करें या यदि आपको लगता है कि यह एक गलत सकारात्मक है तो इस लिस्टिंग को चुनौती दें।