zdrama-virtual[.]icu
“zdrama-virtual | Programmable Communications at Global Scale”
zdrama-virtual.icu — Ошибка сервера (HTTP 502). Олицетворение бренда: Across. Сводка доказательств: VirusTotal 5/93 (alphaMountain.ai, CyRadar, Forcepoint ThreatSeeker, Fortinet, Gridinsoft); URLQuery 1 det.; Spamhaus DBL_PHISH; PhishDestroy score 67/100. Регистратор: NiceNIC.
Подробный анализ PhishDestroy AI ниже оставлен на английском, чтобы сохранить исходную криминалистическую запись.
The domain zdrama-virtual.icu was registered on February 21, 2026 through NiceNIC International Group Co., Limited and currently resolves to the Cloudflare‑owned IP address 104.21.34.75 located in the United States (AS13335). No TLS certificate is in place, and the DNS configuration points to evelyn.ns.cloudflare.com and everton.ns.cloudflare.com, indicating reliance on Cloudflare’s infrastructure. Technical fingerprinting shows Cloudflare Browser Insights, Cloudflare services, and HTTP/3 enabled, which are typical of fast‑cached hosting but do not provide any protective validation for the content.
The site’s HTML title reads "zdrama-virtual | Programmable Communications at Global Scale," a generic phrasing that offers no clear indication of the intended victim audience or lure. VirusTotal analysis returned five positive detections out of ninety‑three scanning engines, and the domain appears on a single public blocklist, further confirming malicious classification. Independent threat‑blocking services, notably PhishDestroy, have already listed the domain, and Gridinsoft assigned a trust score of 0 out of 100, reflecting an extremely low confidence in legitimacy.
As of the report date, July 24, 2026, the site is marked offline, yet its prior activity suggests it was used for generic phishing campaigns. Defenders should continue to block the domain at network perimeter and DNS layers, monitor for any resurgence of the host IP, and consider adding the associated IP range to deny‑list rules. Analysts should also track future registration attempts of similarly patterned domains from the same registrar, as the rapid creation date and use of Cloudflare suggest a disposable‑infrastructure model common to phishing operators.
Данные сетевой безопасности Registrar context
Процесс реагирования на угрозы
Статус в публичных блок-листах
Сохранённый снимок
Аналитика доменов
Технические сведенияDNS, SAN в протоколе SSL, временные метки
ЗОНА SHORTDOT · ПУБЛИЧНЫЕ ДОКАЗАТЕЛЬСТВА
.icu
ShortDot zone evidence
ShortDot zone evidence
The linked repository preserves daily zone observations across seven ShortDot-operated TLDs, including registration volume and abuse-related indicators. This registry context is supporting background and is not an independent detection for the domain in this report.
ICANN OVERSIGHT
Аккредитация и контекст RAA
Аккредитация и контекст RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Latest Classified Outcome 2026-08-14 03:43:04 UTC
Технологии · 3 identified
Performance monitoring tool that measures website speed from real users.
www.cloudflare.comWeb infrastructure and security company providing CDN, DDoS mitigation, and DNS services.
www.cloudflare.comThird major version of HTTP protocol, built on QUIC for faster, more reliable connections.
Анализ VirusTotal
Архивные доказательства
Анализ производительности сайта
Google PageSpeed Insights — mobile performance audit of zdrama-virtual.icu · checked Mar 2, 2026
Доказательства и внешние отчеты
PD-20260218-95FAD4 Recipient: abuse@nicenic.net, abuse@gen.xyz, compliance@icann.org Повлиял ли на вас этот сайт?
Если вы ввели учетные данные, личную или платежную информацию или загрузили файл с этого домена, примите немедленные меры. Ниже приведены ресурсы, которые помогут вам сообщить об инциденте и защитить себя.
Сообщите об этом в местные органы власти
Выберите свою страну, чтобы получить официальные контакты по киберпреступности или создать проект жалобы →.
Проверить любой домен
Анализ угроз с использованием сохраненного черного списка, WHOIS, DNS и общедоступных доказательств сканирования.
Сканировать сейчасСообщить о фишинге
Добавляйте подозрительные домены в нашу базу данных угроз — защищайте сообщество
СообщитьПоток оперативных данных об угрозах
Недавние сообщения о фишинге и наблюдаемые изменения доступности
ОтслеживатьБудьте в курсе событий, берегите себя
Отслеживайте актуальные угрозы или оспорьте эту запись, если считаете, что это ложное срабатывание