zxsc2[.]duomi1[.]cn
“首页”
zxsc2.duomi1.cn — Conteúdo indisponível. Representação da marca: Generic; Tipo de golpe: Impersonation. Resumo das evidências: VirusTotal 5/91 (alphaMountain.ai, CRDF, Gridinsoft, LevelBlue, SOCRadar); URLScan malicious verdict; 2 external blocklist matches (MetaMask, SEAL); PhishDestroy score 90/100. Registrador: 腾讯云计算(北京)有限责任公司.
A análise detalhada do PhishDestroy AI permanece em inglês para preservar o registro forense original.
Analysis on zxsc2.duomi1.cn as of July 23, 2026 indicates that the domain is currently active and classified as a generic phishing threat with a high risk rating. The domain was registered on June 29, 2026 through the Tencent Cloud Computing (Beijing) Limited Liability Company registrar, suggesting a Chinese jurisdiction for the hosting entity. Name resolution points to the IPv4 address 106.55.173.180, and the authoritative name servers are meteorologist.dnspod.net and zenobia.dnspod.net, both operated by the DNSPod service. The domain appears on a single external security blocklist and has been explicitly blocked by the PhishDestroy mitigation platform.
VirusTotal records show that one out of ninety‑one scanned security vendors flagged the domain, confirming at least a minimal level of detection across the threat‑intelligence ecosystem. No additional public intelligence such as Safe Browsing status, OTX tags, SSL certificate details, HTTP response codes, or trust‑score metrics are presently available, leaving the broader surface‑area of the infrastructure unconfirmed. Given the limited detection footprint, defenders should assume that the observed phishing activity may be in early stages or employing evasive techniques that reduce visibility. Immediate mitigation actions include adding zxsc2.duomi1.cn to local and network‑level deny lists, enforcing outbound filtering for the resolved IP address 106.55.173.180, and monitoring DNS queries for the associated nameservers.
Because the registrar is a major cloud provider, requesting takedown or suspension through Tencent Cloud’s abuse channels may accelerate remediation. Continuous re‑evaluation is advised: periodic re‑scans on VirusTotal and other reputation services, as well as verification of any emerging SSL or HTTP characteristics, will help refine the risk posture. Until further evidence emerges, the domain should be treated as high‑risk and proactively blocked in enterprise security controls.
Inteligência de segurança de rede
Pipeline de resposta a ameaças
Status da lista de bloqueios pública
Análise do VirusTotal
Evidências arquivadas
Análise de desempenho do site
Google PageSpeed Insights — mobile performance audit of zxsc2.duomi1.cn · checked Jul 23, 2026
Evidências e relatórios externos
PD-20260723-441442 Recipient: abuse@tencent.com Você foi afetado por este site?
Se você inseriu credenciais de conta, informações pessoais ou de pagamento, ou baixou um arquivo deste domínio, tome medidas imediatas. Abaixo estão os recursos para ajudá-lo a relatar o incidente e se proteger.
Notifique as autoridades locais
Selecione seu país para obter contactos oficiais do cibercrime ou crie um rascunho de reclamação →.
Verificar qualquer domínio
Análise de ameaças usando lista de bloqueio armazenada, WHOIS, DNS e evidências de verificação pública
Digitalize agoraDenunciar phishing
Envie domínios suspeitos para nosso banco de dados de ameaças — proteja a comunidade
DenunciarFeed de ameaças em tempo real
Relatórios recentes de phishing e alterações de disponibilidade observadas
MonitorarMantenha-se informado, mantenha-se seguro
Monitore ameaças em tempo real ou conteste esta listagem caso acredite que se trate de um falso positivo