Notification and current-status evidence
The sent-report ledger records the first outgoing report at .
The recorded recipient is a312636180@gmail.com.
The latest stored availability evidence still shows the domain reachable; 6 months has elapsed since the first outgoing report.
ICANN RAA §3.18 describes registrar abuse-contact and handling obligations. This section records outgoing timestamps, listed recipients, case identifiers, and later availability. It does not by itself prove receipt, acknowledgement, investigation, remediation, or contractual non-compliance.
bing-zoom[.]com[.]cn
“Zoom 视频会议 高效办公沟通必备软件”
bing-zoom.com.cn — Não verificado. Representação da marca: Zoom; Tipo de golpe: Banking Phishing. Resumo das evidências: VirusTotal 4/93 (Fortinet, Gridinsoft, Seclookup, SOCRadar); URLQuery 1 alert; PhishDestroy score 66/100. Registrador: Web Commerce Communica….
A análise detalhada do PhishDestroy AI permanece em inglês para preservar o registro forense original.
On July 24, 2026 the domain bing-zoom.com.cn was observed hosting a malicious page that claims to offer Zoom video‑conference software, as indicated by the HTML title “Zoom 视频会议 高效办公沟通必备软件”. The site explicitly impersonates the Zoom brand, a fact corroborated by the provided brand target field. Registration records show the domain was created on 21 February 2026 and was registered through Web Commerce Communications Limited. The authoritative name servers listed are a12.share-dns.com and b12.share-dns.net, which resolve the domain to the IPv4 address 154.195.66.107. The IP resides in Hong Kong and is announced by AS9294 (GNET INC.).
Network fingerprints reveal the web server is Nginx and the site serves an HSTS header, although no TLS certificate is presented, meaning the connection is unencrypted HTTP. An HTTP GET request returns status code 200, confirming the page is reachable despite the lack of SSL. The malicious activity is classified as banking phishing, suggesting the page attempts to harvest financial credentials. VirusTotal analysis reports that 4 of 93 scanned security vendors flagged the domain, indicating a moderate level of detection. Independent blocklist providers PhishDestroy, MetaMask, and SEAL have already added the domain to their deny lists, and the domain appears on three additional security blocklists.
The current operational status is “offline”, implying the site has been taken down or is no longer serving content. Defenders should update perimeter controls to block any DNS resolution of bing-zoom.com.cn, enforce HTTP to HTTPS redirection policies that would drop unencrypted connections, and add the associated IP address 154.195.66.107 to network‑level deny lists. Email security gateways should incorporate the domain into phishing detection rules, especially given its banking‑phishing profile. Continuous monitoring of the registrar Web Commerce Communications Limited and the underlying hosting AS may reveal future infrastructure reuse.
Inteligência de segurança de rede
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| Hagezi Threat Feed | bing-zoom.com.cn |
malicious | Sinkholed |
Pipeline de resposta a ameaças
Status da lista de bloqueios pública
Tecnologias · 2 identified
High-performance HTTP server and reverse proxy, known for stability and low resource usage.
HTTP Strict Transport Security — forces browsers to use HTTPS connections only.
Análise do VirusTotal
Evidências arquivadas
Evidências e relatórios externos
PD-20260202-132814 Recipient: a312636180@gmail.com Você foi afetado por este site?
Se você inseriu credenciais de conta, informações pessoais ou de pagamento, ou baixou um arquivo deste domínio, tome medidas imediatas. Abaixo estão os recursos para ajudá-lo a relatar o incidente e se proteger.
Notifique as autoridades locais
Selecione seu país para obter contactos oficiais do cibercrime ou crie um rascunho de reclamação →.
Verificar qualquer domínio
Análise de ameaças usando lista de bloqueio armazenada, WHOIS, DNS e evidências de verificação pública
Digitalize agoraDenunciar phishing
Envie domínios suspeitos para nosso banco de dados de ameaças — proteja a comunidade
DenunciarFeed de ameaças em tempo real
Relatórios recentes de phishing e alterações de disponibilidade observadas
MonitorarMantenha-se informado, mantenha-se seguro
Monitore ameaças em tempo real ou conteste esta listagem caso acredite que se trate de um falso positivo