zoommeetlink[.]us
“Zoom Meeting | Secure Video Conference”
zoommeetlink.us — Conteúdo indisponível (HTTP 502). Representação da marca: ["zoom"]. Resumo das evidências: VirusTotal 1/93 (SOCRadar); 2 external blocklist matches (MetaMask, SEAL); PhishDestroy score 66/100. Registrador: NameSilo.
A análise detalhada do PhishDestroy AI permanece em inglês para preservar o registro forense original.
Analysis of zoommeetlink.us shows a newly registered domain created on February 27, 2026 and hosted on IP address 104.225.128.78, which belongs to AS395092 Shock Hosting LLC in the United States. The domain resolves to that single address and is served without an SSL certificate, indicating an absence of encrypted transport. Registration was performed through NameSilo, LLC and the authoritative name servers are listed as ns3.loominost.com and ns4.loominost.com. The page title returned from the live endpoint is "Zoom Meeting | Secure Video Conference," suggesting an attempt to impersonate a legitimate video‑conference service.
The site has been added to three public blocklists and is currently listed as blocked by PhishDestroy, MetaMask, and SEAL. VirusTotal scanning shows that one out of ninety‑three security vendors flagged the domain, confirming at least one independent detection. The domain’s status is reported as offline, which limits further real‑time observation, but the historical evidence points to a short‑lived phishing campaign targeting Zoom users. Uncertainty remains around the specific phishing kit or payload, as no additional payload hashes, redirect chains, or credential‑stealing forms have been disclosed.
Defenders should continue to block the domain at network perimeter controls, update DNS filtering with the known blocklists, and monitor for any resurgence of the same IP or name‑server configuration. Because the site lacks TLS, any attempt to access it would be over clear‑text HTTP, providing an additional mitigation surface. Threat‑intel teams should flag the domain in internal watchlists and correlate any future Zoom‑related credential‑theft alerts with this indicator to reduce exposure.
Inteligência de segurança de rede Registrar context
Pipeline de resposta a ameaças
Status da lista de bloqueios pública
Análise do VirusTotal
Evidências e relatórios externos
PD-20260227-707CE5 Recipient: abuse@namesilo.com Você foi afetado por este site?
Se você inseriu credenciais de conta, informações pessoais ou de pagamento, ou baixou um arquivo deste domínio, tome medidas imediatas. Abaixo estão os recursos para ajudá-lo a relatar o incidente e se proteger.
Notifique as autoridades locais
Selecione seu país para obter contactos oficiais do cibercrime ou crie um rascunho de reclamação →.
Verificar qualquer domínio
Análise de ameaças usando lista de bloqueio armazenada, WHOIS, DNS e evidências de verificação pública
Digitalize agoraDenunciar phishing
Envie domínios suspeitos para nosso banco de dados de ameaças — proteja a comunidade
DenunciarFeed de ameaças em tempo real
Relatórios recentes de phishing e alterações de disponibilidade observadas
MonitorarMantenha-se informado, mantenha-se seguro
Monitore ameaças em tempo real ou conteste esta listagem caso acredite que se trate de um falso positivo