MALICIOUS — CRITICAL
Проверка домена us05web-meet.com на фишинг и безопасность
us05web-meet[.]
The domain us05web-meet.com was registered on 21 February 2026 through PDR Ltd.
- VirusTotal
- 11/91
- Blocklists
- 2 · MetaMask, SEAL
- Доступность
- Последний известный активный · HTTP 200
Do not enter credentials, seed phrases, payment details, or personal information on this domain.
Notification and current-status evidence
The sent-report ledger records the first outgoing report at .
The recorded recipient is abuse-contact@publicdomainregistry.com.
The latest stored availability evidence still shows the domain reachable; 6 months has elapsed since the first outgoing report.
ICANN RAA §3.18 describes registrar abuse-contact and handling obligations. This section records outgoing timestamps, listed recipients, case identifiers, and later availability. It does not by itself prove receipt, acknowledgement, investigation, remediation, or contractual non-compliance.
Jump to section
us05web-meet.com — Последний известный активный (HTTP 200). Олицетворение бренда: Google; Тип мошенничества: Brand Impersonation. Сводка доказательств: VirusTotal 11/91 (ADMINUSLabs, alphaMountain.ai, BitDefender, Chong Lua Dao, CyRadar); Spamhaus DBL_SPAM; 2 external blocklist matches (MetaMask, SEAL); PhishDestroy score 93/100. Регистратор: PDR.
Подробный анализ PhishDestroy AI ниже оставлен на английском, чтобы сохранить исходную криминалистическую запись.
Evidence Analysis
The domain us05web-meet.com was registered on 21 February 2026 through PDR Ltd. d/b/a PublicDomainRegistry.com and is currently hosted on the IP address 101.99.93.38, which resolves to an autonomous system (AS45839) owned by Shinjiru Technology Sdn Bhd in Bulgaria. DNS records point to the authoritative nameservers ns1.aitscb.com and ns2.aitscb.com. The web server reports an Apache HTTP Server banner and presents a TLS certificate issued by Let’s Encrypt (R13), indicating that encrypted connections are available. An HTTP GET returns status code 200 and the sole page title is “Index of /”, suggesting a directory listing without additional content.
The site is classified as a brand‑impersonation campaign targeting Google, and the risk level is marked high with an active status. VirusTotal analysis shows that six of ninety‑three scanning engines have flagged the domain, and three independent blocklists already list it. Commercial filtering services such as PhishDestroy, MetaMask and SEAL have also blocked the domain. The Gridinsoft trust score is 0 out of 100, reinforcing the malicious assessment.
No further payload or credential‑harvesting pages have been observed in the public data, so the exact phishing kit or content remains unknown. Defenders should continue to block the domain at perimeter and DNS layers, monitor outbound connections to the associated IP range, and add the domain and its nameservers to threat‑intel feeds. Given the active status and high risk rating, security teams should also consider automated sandbox retrieval of the site content to verify any future changes. Continuous re‑scanning with VirusTotal or similar services is advised to capture additional detections as the campaign evolves.
Stored source results
Recorded verdicts and infrastructure observations for this domain.
Охват данных12 recorded checks
Процесс реагирования на угрозы
Статус в публичных блок-листах
Сохранённый снимок
Аналитика доменов
Технические сведенияDNS, SAN в протоколе SSL, временные метки
ICANN OVERSIGHT
Аккредитация и контекст RAA
Аккредитация и контекст RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Технологии · 1 identified
Most widely used open-source HTTP server software.
Анализ VirusTotal
Архивные доказательства
Доказательства и внешние отчетыIndependent lookups and source reports
PD-20260206-9F9AB5 Recipient: abuse-contact@publicdomainregistry.com Victim safety and official reportingImmediate actions and verified reporting channels
Если вы ввели учетные данные, личную или платежную информацию или загрузили файл с этого домена, примите немедленные меры. Ниже приведены ресурсы, которые помогут вам сообщить об инциденте и защитить себя.
Сообщите об этом в местные органы власти
Выберите свою страну, чтобы получить официальные контакты по киберпреступности или создать проект жалобы →.