zoom-premium[.]click
“ZOOM PREMIUM”
Сводка доказательств
The domain zoom-premium.click is a confirmed phishing site engaged in brand impersonation targeting Zoom users. It presents itself as a 'ZOOM PREMIUM' service to deceive victims into entering login credentials or other sensitive information. No crypto drainer kit was detected, but the site poses an elevated risk due to its fraudulent representation of the Zoom brand. As of the latest verification, zoom-premium.click has been taken offline.
Technical indicators confirm the malicious nature of zoom-premium.click. The domain was flagged by 3 of 95 security vendors on VirusTotal, including Gridinsoft, Seclookup, and SOCRadar, with a Gridinsoft trust score of 0/100. It appears on 3 security blocklists: PhishDestroy, MetaMask, and SEAL. Registered through HOSTINGER operations, UAB on February 21, 2026, the domain resolves to IP address 46.202.138.75, hosted by AS47583 Hostinger International Limited in Indonesia. No SSL certificate was issued, and the nameservers are ns1.dns-parking.com and ns2.dns-parking.com. The observed page title was 'ZOOM PREMIUM'.
Individuals who interacted with zoom-premium.click should immediately change any passwords entered on the site, especially for Zoom or linked accounts, and enable two-factor authentication (2FA) where available. Monitor accounts for unauthorized activity and report any suspected fraud to the impersonated brand, Zoom, and relevant authorities. Victims may also report the domain to their local cybercrime unit or platforms like Google Safe Browsing, PhishTank, or the Anti-Phishing Working Group (APWG) to aid in takedown efforts.
Снимок отправленных доказательств
- Отправлено
- Записи журнала
- 1
- ID дела
PD-20260208-7CEA5E- PDF-файл
- PDF с доказательствами
Правовое основание
Полный текст доказательств
Acceptable Use Policy (AUP): The domain zoom-premium.click is engaged in phishing activities, which directly contravenes the AUP's prohibition against illegal activities and deception.
Terms of Service (TOS): The registrar reserves the right to suspend or terminate services for violations, and the fraudulent nature of this domain clearly warrants immediate action under this provision.
Applicable Laws (Unknown):
Computer Fraud and Abuse Act (CFAA): This U.S. law prohibits unauthorized access to computers and fraudulent activities, which are applicable to phishing schemes.
Wire Fraud Statute (18 U.S.C. § 1343): This law criminalizes schemes to defraud individuals or entities using electronic communications, which is relevant to the activities associated with this domain.
CAN-SPAM Act (15 U.S.C. § 7701): This act regulates commercial email and prohibits misleading headers and deceptive subject lines, which are often utilized in phishing attempts.
Regulatory Note: Failure to take prompt action against zoom-premium.click may expose your organization to legal liability and regulatory scrutiny. Non-compliance with your own policies and applicable laws could result in significant penalties.
Data Coverage
Данные сетевой безопасности
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| Hagezi Threat Feed | zoom-premium.click |
malicious | Sinkholed |
Процесс реагирования на угрозы
Проверка по блок-листам
10 внешних источников под наблюдением · снимок от 13.08.2026
8 внешних источников под наблюдением Совпадений нет
Хронология обнаружения
-
Cloudflare Radar
Сканирование Cloudflare Radar сохранено · Открыть сканирование
Сохранённый снимок
Аналитика доменов
Технические деталиDNS, имена TLS и временные метки
ICANN OVERSIGHT
Аккредитация и контекст RAA
Аккредитация и контекст RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Анализ VirusTotal
Повлиял ли на вас этот сайт?
Если вы ввели учетные данные, личную или платежную информацию или загрузили файл с этого домена, примите немедленные меры. Ниже приведены ресурсы, которые помогут вам сообщить об инциденте и защитить себя.
Сообщите об этом в местные органы власти
Выберите свою страну, чтобы получить официальные контакты по киберпреступности или создать проект жалобы →.
Проверить любой домен
Анализ угроз с использованием сохраненного черного списка, WHOIS, DNS и общедоступных доказательств сканирования.
Сканировать сейчасСообщить о фишинге
Добавляйте подозрительные домены в нашу базу данных угроз — защищайте сообщество
СообщитьПоток оперативных данных об угрозах
Недавние сообщения о фишинге и наблюдаемые изменения доступности
ОтслеживатьБудьте в курсе событий, берегите себя
Отслеживайте актуальные угрозы или оспорьте эту запись, если считаете, что это ложное срабатывание