web04zoom[.]im
Resumo das evidências
The domain web04zoom.im is identified as a credential harvesting phishing infrastructure targeting users through deceptive login interfaces. Analysis indicates the domain is currently offline, though it previously hosted active phishing content designed to capture sensitive authentication details. No direct brand impersonation has been confirmed, but the domain structure suggests an intent to mimic legitimate communication platforms. Infrastructure analysis reveals the domain was registered through an anonymized registrar on February 21, 2026, and has been flagged by 19 of 95 security vendors on VirusTotal. It appears on three distinct security blocklists, including entries from high-confidence threat intelligence sources. The domain's creation date aligns with recent phishing campaign timelines, and its hosting infrastructure was previously linked to a known malicious IP range, though current resolution attempts return no active records. No associated SSL certificates or subdomains have been observed in recent scans. Given the domain's current offline status, immediate risk to end users is reduced, though residual threats may persist through cached or archived content. Organizations are advised to update internal blocklists to include web04zoom.im and monitor for any attempts to re-register or re-host the domain. Network administrators should review logs for prior connections to this domain and implement DNS-based blocking rules to prevent future access. End users who may have interacted with the domain should reset credentials for any accounts accessed during the exposure window and enable multi-factor authentication where available.
Data Coverage
Inteligência de segurança de rede
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| DigiCert UltraDNS | cold-na-phx-4.gofile.io |
malicious | Sinkholed |
| DigiCert UltraDNS | cold-na-phx-9.gofile.io |
malicious | Sinkholed |
Pipeline de resposta a ameaças
Cobertura de listas de bloqueio
10 fontes externas monitoradas · instantâneo de 12/08/2026
10 fontes externas monitoradas Sem correspondência
Linha do tempo de detecção
-
Cloudflare Radar
Varredura do Cloudflare Radar armazenada · Abrir varredura
-
Cloudflare Radar
Varredura do Cloudflare Radar armazenada · Abrir varredura
Captura armazenada
Inteligência de Domínios
Detalhes técnicosDNS, nomes TLS e datas
Análise do VirusTotal
Você foi afetado por este site?
Se você inseriu credenciais de conta, informações pessoais ou de pagamento, ou baixou um arquivo deste domínio, tome medidas imediatas. Abaixo estão os recursos para ajudá-lo a relatar o incidente e se proteger.
Notifique as autoridades locais
Selecione seu país para obter contactos oficiais do cibercrime ou crie um rascunho de reclamação →.
Verificar qualquer domínio
Análise de ameaças usando lista de bloqueio armazenada, WHOIS, DNS e evidências de verificação pública
Digitalize agoraDenunciar phishing
Envie domínios suspeitos para nosso banco de dados de ameaças — proteja a comunidade
DenunciarFeed de ameaças em tempo real
Relatórios recentes de phishing e alterações de disponibilidade observadas
MonitorarMantenha-se informado, mantenha-se seguro
Monitore ameaças em tempo real ou conteste esta listagem caso acredite que se trate de um falso positivo