us15webs[.]us
“One platform to connect | Zoom”
Riepilogo delle prove
us15webs.us was observed by multiple detection sources as a phishing‑related site. The domain was registered on 21 February 2026 through CNOBIN INFORMATION TECHNOLOGY LIMITED and currently shows an offline HTTP status. DNS resolution points to 172.67.189.107, an address owned by Cloudflare (AS13335) located in the United States. Both authoritative nameservers are Cloudflare‑managed (justin.ns.cloudflare.com, margot.ns.cloudflare.com). No TLS certificate is presented for the host, indicating that HTTPS was not configured at the time of observation.
The page title returned from the HTTP response is "One platform to connect | Zoom", suggesting an attempt to impersonate Zoom’s branding, although the content of the page has not been captured. Gridinsoft assigns a trust score of 0 out of 100, and the domain appears on three public blocklists. VirusTotal recorded a single positive detection out of 93 scanned scanners. Additional blocklist feeds from PhishDestroy, MetaMask and SEAL also list the domain.
Because the site is already taken offline, immediate mitigation is limited to ensuring that any cached or historic references are blocked in perimeter defenses. Organizations should add the domain and its resolving IP to web filtering and intrusion‑prevention rules, and monitor for any resurgence of the same registrar or Cloudflare IP range in future phishing campaigns. Continuous verification of the DNS records is recommended, as Cloudflare‑hosted infrastructure can be rapidly repurposed. The limited detection footprint—one VirusTotal hit and three blocklist entries—leaves the full scope of the phishing campaign uncertain; further investigation of the original payload or any associated command‑and‑control infrastructure would be required to fully assess impact.
Data Coverage
Pipeline di risposta alle minacce
Copertura delle blocklist
10 fonti esterne monitorate · snapshot del 10/08/2026
10 fonti esterne monitorate Nessuna corrispondenza
Cronologia del rilevamento
-
Cloudflare Radar
Scansione Cloudflare Radar archiviata · Apri scansione
Analisi di VirusTotal
Questo sito ti ha influenzato in qualche modo?
Se hai inserito credenziali dell'account, informazioni personali o di pagamento oppure hai scaricato un file da questo dominio, agisci immediatamente. Di seguito sono riportate le risorse per aiutarti a segnalare l'incidente e proteggerti.
Segnalalo alle autorità locali
Seleziona il tuo Paese per ottenere contatti ufficiali del crimine informatico o creare una bozza di reclamo →.
Verifica qualsiasi dominio
Analisi delle minacce utilizzando blocklist archiviate, WHOIS, DNS e prove di scansione pubblica
Scansiona oraSegnala un tentativo di phishing
Segnala i domini sospetti al nostro database delle minacce — proteggi la comunità
SegnalaFeed in tempo reale sulle minacce
Segnalazioni recenti di phishing e modifiche osservate della disponibilità
MonitoraRimani informato, rimani al sicuro
Controlla le minacce in tempo reale oppure contesta questa segnalazione se ritieni che si tratti di un falso positivo