us0lwebzoom[.]us
Verifica phishing e sicurezza per us0lwebzoom.us
us0lwebzoom.us — Contenuto non disponibile (HTTP 502). Riepilogo delle prove: VirusTotal 2/93 (alphaMountain.ai, SOCRadar); 2 external blocklist matches (MetaMask, SEAL); PhishDestroy score 66/100. Registrar: NameSilo.
L’analisi dettagliata di PhishDestroy AI resta in inglese per preservare il rapporto forense originale.
Analysis of us0lwebzoom.us indicates that the domain was registered on 21 February 2026 through NameSilo, LLC and points to the IP address 188.227.197.32, which is allocated to PETROSKY CLOUD LLC in Canada under ASN 400897. The domain resolves via the DNS Owl nameserver set (ns1.dnsowl.com, ns2.dnsowl.com, ns3.dnsowl.com) and does not present an SSL/TLS certificate, implying unencrypted HTTP communication. VirusTotal records show that two of ninety‑three scanning engines flagged the host, and the domain appears on three external blocklists. It is currently listed as blocked by PhishDestroy, MetaMask, and SEAL, and the overall status is marked offline, suggesting that the malicious site has been taken down or is no longer reachable.
The available evidence points to a generic phishing operation, although the specific lure, target brand, or compromised credential collection method has not been disclosed in the public data. Absence of a certificate and the recent registration date are consistent with opportunistic phishing deployments that rely on fast‑flux style infrastructure. Because the site is already offline, immediate mitigation focuses on preventing future re‑use of the same infrastructure.
Defenders should add the domain and its associated IP address to internal blocklists, monitor DNS queries for the listed nameservers, and watch for any new domains registered by the same registrar or ASN that exhibit similar characteristics. Continuous re‑scanning on VirusTotal and inclusion in URL filtering services is recommended to catch any re‑appearance. Until further artefacts such as page titles or payload samples become available, the threat remains classified as elevated due to the combination of recent creation, low detection coverage, and confirmed blocklist listings.
Informazioni sulla sicurezza di rete Registrar context
Pipeline di risposta alle minacce
Stato della lista di blocco pubblica
Acquisizione salvata
Analisi dei domini
Dettagli tecniciDNS, SAN SSL, timestamp
Analisi di VirusTotal
Dati e relazioni esterne
PD-20260210-825E45 Recipient: abuse@namesilo.com Questo sito ti ha influenzato in qualche modo?
Se hai inserito credenziali dell'account, informazioni personali o di pagamento oppure hai scaricato un file da questo dominio, agisci immediatamente. Di seguito sono riportate le risorse per aiutarti a segnalare l'incidente e proteggerti.
Segnalalo alle autorità locali
Seleziona il tuo Paese per ottenere contatti ufficiali del crimine informatico o creare una bozza di reclamo →.
Verifica qualsiasi dominio
Analisi delle minacce utilizzando blocklist archiviate, WHOIS, DNS e prove di scansione pubblica
Scansiona oraSegnala un tentativo di phishing
Segnala i domini sospetti al nostro database delle minacce — proteggi la comunità
SegnalaFeed in tempo reale sulle minacce
Segnalazioni recenti di phishing e modifiche osservate della disponibilità
MonitoraRimani informato, rimani al sicuro
Controlla le minacce in tempo reale oppure contesta questa segnalazione se ritieni che si tratti di un falso positivo