zoomoutlet[.]pl
“Bid on the domain zoomoutlet.pl now | nicsell”
zoomoutlet.pl — Não verificado. Representação da marca: Zoom; Tipo de golpe: Brand Impersonation. Resumo das evidências: VirusTotal 5/91 (alphaMountain.ai, CRDF, Forcepoint ThreatSeeker, Gridinsoft, SOCRadar); 2 external blocklist matches (MetaMask, SEAL); PhishDestroy score 78/100. Registrador: DomainProfi.
A análise detalhada do PhishDestroy AI permanece em inglês para preservar o registro forense original.
The domain zoomoutlet.pl was registered on 27 May 2026 through DomainProfi GmbH, a registrar based in Germany. It is currently active and resolves to a single IPv4 address (195.201.69.223). The site presents a landing page titled “Bid on the domain zoomoutlet.pl now | nicsell”, which is typical of malicious domain‑parking services used to lure victims.
Network analysis shows the host resides in Germany and is hosted by DomainProfi GmbH. The authoritative name servers are ns1.nicsell.com and ns2.nicsell.com, both resolving to the same IP address. An HTTPS endpoint is available using a Let’s Encrypt certificate (issuer E8) and the server returns HTTP 200 for the landing page, indicating a fully functional web service.
Threat intelligence feeds have listed zoomoutlet.pl on three security blocklists, and it is flagged by PhishDestroy, MetaMask, and SEAL as malicious. The Gridinsoft trust score is 0 out of 100, confirming a low reputation. VirusTotal scans show 2 of 95 vendors marking the domain as malicious, which aligns with the blocklist findings. The low trust score and blocklist presence suggest the site is part of a broader generic phishing operation.
Defenders should block any outbound connections to 195.201.69.223 and add zoomoutlet.pl to DNS deny lists. Email gateways should treat any messages containing this domain as malicious and quarantine them. Because the landing page currently only displays a parking notice, the exact phishing payload or credential‑harvesting mechanism remains unknown, and threat actors may later replace it with a credential‑stealing form. Continuous monitoring of the associated name servers (ns1.nicsell.com, ns2.nicsell.com) is advised, as they may host additional phishing content in the future.
Pipeline de resposta a ameaças
Status da lista de bloqueios pública
Inteligência de Domínios
Detalhes técnicosDNS, SANs do SSL, carimbos de data e hora
Análise do VirusTotal
Evidências e relatórios externos
Você foi afetado por este site?
Se você inseriu credenciais de conta, informações pessoais ou de pagamento, ou baixou um arquivo deste domínio, tome medidas imediatas. Abaixo estão os recursos para ajudá-lo a relatar o incidente e se proteger.
Notifique as autoridades locais
Selecione seu país para obter contactos oficiais do cibercrime ou crie um rascunho de reclamação →.
Verificar qualquer domínio
Análise de ameaças usando lista de bloqueio armazenada, WHOIS, DNS e evidências de verificação pública
Digitalize agoraDenunciar phishing
Envie domínios suspeitos para nosso banco de dados de ameaças — proteja a comunidade
DenunciarFeed de ameaças em tempo real
Relatórios recentes de phishing e alterações de disponibilidade observadas
MonitorarMantenha-se informado, mantenha-se seguro
Monitore ameaças em tempo real ou conteste esta listagem caso acredite que se trate de um falso positivo