us95webs[.]us
Pemeriksaan phishing dan keamanan us95webs.us
“One platform to connect | Zoom”
us95webs.us — Konten tidak tersedia (HTTP 502). Peniruan identitas merek: Across; Jenis penipuan: Brand Impersonation. Ringkasan bukti: VirusTotal 2/93 (Fortinet, SOCRadar); Spamhaus DBL_PHISH; 2 external blocklist matches (MetaMask, SEAL); PhishDestroy score 66/100. Registrar: Web Commerce Communica….
Analisis terperinci PhishDestroy AI di bawah tetap berbahasa Inggris untuk menjaga catatan forensik asli.
us95webs.us was observed resolving to the IP address 170.114.78.80, which belongs to the Cloudflare network (AS13335) and is geolocated in the United States. The domain was registered on 21 February 2026 through Web Commerce Communications Limited and uses the Cloudflare nameservers justin.ns.cloudflare.com and margot.ns.cloudflare.com. No TLS certificate is presented, indicating that the site was served over plain HTTP at the time of collection. The page title returned by the server is “One platform to connect | Zoom”, which directly references Zoom’s branding and aligns with the classification of a brand‑impersonation campaign targeting Zoom users.
The domain appears on three independent blocklists—PhishDestroy, MetaMask, and SEAL—demonstrating that multiple security vendors have identified it as malicious. VirusTotal analysis shows that two of ninety‑three scanning engines flagged the site, providing additional corroboration of its malicious intent. Gridinsoft assigned a trust score of zero out of one hundred, reinforcing the conclusion that the infrastructure is considered highly untrustworthy. The current operational status is offline, which may reflect takedown actions or a temporary suspension by the hosting provider.
Uncertainties remain regarding the specific payload or credential‑harvesting mechanisms employed, as no further page content or network traffic has been captured. Defenders should continue to block the domain and its associated IP address at perimeter firewalls, update DNS filtering solutions with the listed blocklist entries, and monitor for newly registered domains that resolve to the same Cloudflare IP range and use similar naming patterns. Ongoing vigilance is advised given the recent creation date and the low trust score, which suggest that the actors may attempt to re‑deploy the campaign using new domains.
Alur Tanggapan Ancaman Pipeline
Status Daftar Blokir Publik
Analisis VirusTotal
Bukti & Laporan Eksternal
PD-20260203-D02629 Recipient: compliance_abuse@webnic.cc Apakah Anda Terpengaruh oleh Situs Ini?
Jika Anda memasukkan kredensial akun, informasi pribadi atau pembayaran, atau mengunduh file dari domain ini, segera ambil tindakan. Di bawah ini adalah sumber daya untuk membantu Anda melaporkan insiden tersebut dan melindungi diri Anda sendiri.
Laporkan kepada Pihak Berwenang di Daerah Anda
Pilih negara Anda untuk mendapatkan kontak resmi kejahatan dunia maya, atau membuat draf pengaduan →.
Periksa Domain Apa Pun
Analisis ancaman menggunakan daftar blokir yang disimpan, WHOIS, DNS, dan bukti pemindaian publik
Pindai SekarangLaporkan Phishing
Laporkan domain yang mencurigakan ke basis data ancaman kami — lindungi komunitas
LaporanPemberitahuan Ancaman Real-Time
Laporan phishing terbaru dan perubahan ketersediaan yang diamati
PantauTetap Terinformasi, Tetap Aman
Pantau ancaman secara langsung atau ajukan keberatan terhadap daftar ini jika Anda yakin ini merupakan false positive