MALICIOUS — CRITICAL
zoomlink[.]pt
The domain zoomlink.pt is flagged for brand impersonation targeting Zoom.
- VirusTotal
- 8/91
- Blocklists
- 2 · MetaMask, SEAL
- Доступность
- Последний известный активный · HTTP 200
Do not enter credentials, seed phrases, payment details, or personal information on this domain.
Notification and current-status evidence
The sent-report ledger records the first outgoing report at .
The recorded recipient is abuse@webtuga.pt.
The latest stored availability evidence still shows the domain reachable; 4 months has elapsed since the first outgoing report.
ICANN RAA §3.18 describes registrar abuse-contact and handling obligations. This section records outgoing timestamps, listed recipients, case identifiers, and later availability. It does not by itself prove receipt, acknowledgement, investigation, remediation, or contractual non-compliance.
Jump to section
zoomlink.pt — Последний известный активный (HTTP 200). Олицетворение бренда: Zoom; Тип мошенничества: Generic Phishing. Сводка доказательств: VirusTotal 8/91 (alphaMountain.ai, BitDefender, Chong Lua Dao, CRDF, CyRadar); 2 external blocklist matches (MetaMask, SEAL); PhishDestroy score 84/100.
Подробный анализ PhishDestroy AI ниже оставлен на английском, чтобы сохранить исходную криминалистическую запись.
Evidence Analysis
The domain zoomlink.pt is flagged for brand impersonation targeting Zoom. Registered on January 06 2011 the domain remains active with an HTTP 200 response and page title Site is undergoing maintenance. Infrastructure analysis reveals resolution to IP 185.240.248.34 hosted in Portugal under AS39384 with nameservers ns1.wtservers.com ns2.wtservers.com and ns3.wtservers.com. The MX record points back to zoomlink.pt itself and the certificate is issued by Let's Encrypt R12. Detected technologies include WordPress MySQL PHP Nginx jQuery Migrate and jQuery.
Gridinsoft assigns a trust score of 0/100 while VirusTotal reports 2/95 vendors flagging the domain. The domain appears on three blocklists including PhishDestroy MetaMask and SEAL. The impersonation classification aligns with the reported scam type of Generic Phishing and the high risk level assigned to the active instance.
Defenders should block the IP 185.240.248.34 and all associated nameservers at network and endpoint layers. Monitor for any resolution changes or certificate renewals and correlate traffic to this domain against internal logs for potential credential or session data exposure. Continued observation of the maintenance page status is warranted given the domain age and persistent activity indicators.
Охват данных12 recorded checks
Процесс реагирования на угрозы
Статус в публичных блок-листах
Криминалистическая аналитика
Технологии · 6 identified
Open-source CMS powering over 40% of websites worldwide.
Open-source relational database management system.
Server-side scripting language designed for web development.
High-performance HTTP server and reverse proxy, known for stability and low resource usage.
Plugin to detect and restore deprecated jQuery features.
Fast, small JavaScript library simplifying HTML manipulation, event handling, and Ajax.
Анализ VirusTotal
Анализ производительности сайта
Google PageSpeed Insights — mobile performance audit of zoomlink.pt · checked Mar 18, 2026
Доказательства и внешние отчетыIndependent lookups and source reports
PD-20260318-156C85 Recipient: abuse@webtuga.pt Victim safety and official reportingImmediate actions and verified reporting channels
Если вы ввели учетные данные, личную или платежную информацию или загрузили файл с этого домена, примите немедленные меры. Ниже приведены ресурсы, которые помогут вам сообщить об инциденте и защитить себя.
Сообщите об этом в местные органы власти
Выберите свою страну, чтобы получить официальные контакты по киберпреступности или создать проект жалобы →.