Notification and current-status evidence
The sent-report ledger records the first outgoing report at .
The recorded recipient is a312636180@gmail.com.
The latest stored availability evidence still shows the domain reachable; 6 months has elapsed since the first outgoing report.
ICANN RAA §3.18 describes registrar abuse-contact and handling obligations. This section records outgoing timestamps, listed recipients, case identifiers, and later availability. It does not by itself prove receipt, acknowledgement, investigation, remediation, or contractual non-compliance.
zm-zoom[.]com[.]cn
“高效视频会议选 Zoom 专业协作办公软件”
zm-zoom.com.cn — Непроверенный. Олицетворение бренда: Google; Тип мошенничества: Impersonation. Сводка доказательств: VirusTotal 3/91 (alphaMountain.ai, Chong Lua Dao, Gridinsoft); URLQuery 1 alert; PhishDestroy score 78/100. Регистратор: Web Commerce Communica….
Подробный анализ PhishDestroy AI ниже оставлен на английском, чтобы сохранить исходную криминалистическую запись.
Analysis indicates that the domain zm-zoom.com.cn was registered on February 21, 2026 through Web Commerce Communications Limited. The domain resolves to IP 154.195.66.111, which belongs to AS9294 GNET INC. in Hong Kong. No TLS certificate is presented; HTTP connections are unencrypted and the site is currently taken offline. The page title observed before takedown reads “高效视频会议选 Zoom 专业协作办公软件”, which references Zoom but the threat intelligence tags the site as impersonating Google.
This inconsistency suggests a possible attempt to lure victims by mixing brand references. The domain appears on three public blocklists and is specifically flagged by PhishDestroy, MetaMask, and SEAL. VirusTotal scans show that six of ninety‑three security vendors submitted a detection for the domain, reinforcing its malicious classification. The nameservers listed are a.share-dns.com, a8.share-dns.com, b.share-dns.net, and b8.share-dns.net, a pattern observed in other malicious infrastructure. Gridinsoft assigns a trust score of zero out of one hundred, indicating no confidence in the site's legitimacy.
Given the lack of an SSL certificate, the offline status, and the limited publicly available content, the precise phishing workflow cannot be fully reconstructed. However, the combination of brand impersonation, low trust score, blocklist presence, and partial VirusTotal detections provides sufficient evidence for defensive action. Organizations should add zm-zoom.com.cn to web‑filter deny lists, ensure DNS resolvers block queries to the associated IP, and monitor for any new domains sharing the same registrar or naming‑server pattern. Security telemetry should also be tuned to flag any HTTP traffic to the domain or attempts to resolve it, as threat actors may reactivate the site or deploy a clone. Continuous review of blocklist updates and VirusTotal re‑scans is recommended to capture any changes in the domain's status.
Данные сетевой безопасности
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| Hagezi Threat Feed | zm-zoom.com.cn |
malicious | Sinkholed |
Процесс реагирования на угрозы
Статус в публичных блок-листах
Анализ VirusTotal
Архивные доказательства
Доказательства и внешние отчеты
PD-20260202-97DA57 Recipient: a312636180@gmail.com Повлиял ли на вас этот сайт?
Если вы ввели учетные данные, личную или платежную информацию или загрузили файл с этого домена, примите немедленные меры. Ниже приведены ресурсы, которые помогут вам сообщить об инциденте и защитить себя.
Сообщите об этом в местные органы власти
Выберите свою страну, чтобы получить официальные контакты по киберпреступности или создать проект жалобы →.
Проверить любой домен
Анализ угроз с использованием сохраненного черного списка, WHOIS, DNS и общедоступных доказательств сканирования.
Сканировать сейчасСообщить о фишинге
Добавляйте подозрительные домены в нашу базу данных угроз — защищайте сообщество
СообщитьПоток оперативных данных об угрозах
Недавние сообщения о фишинге и наблюдаемые изменения доступности
ОтслеживатьБудьте в курсе событий, берегите себя
Отслеживайте актуальные угрозы или оспорьте эту запись, если считаете, что это ложное срабатывание