zoommeetingsinvitees[.]com
“Download Zoom”
zoommeetingsinvitees.com — Контент недоступен (HTTP 502). Олицетворение бренда: Zoom; Тип мошенничества: Brand Impersonation. Сводка доказательств: VirusTotal 17/93 (ADMINUSLabs, alphaMountain.ai, Certego, Cluster25, CRDF); URLQuery 2 alerts; URLScan malicious verdict; PhishDestroy score 95/100. Регистратор: NameSilo.
Подробный анализ PhishDestroy AI ниже оставлен на английском, чтобы сохранить исходную криминалистическую запись.
The domain zoommeetingsinvitees.com was registered on February 21 2026 through NameSilo, LLC. DNS resolution points to the IPv4 address 89.163.155.33, which is announced by AS24961 (WIIT AG) and geolocated to Germany. The authoritative name servers are ns7.privatedns.vip and ns8.privatedns.vip, both of which are commonly used by malicious infrastructure. No TLS certificate is presented, indicating the site is served only over HTTP, which further reduces trust. The HTTP response currently returns an offline status, confirming that the site is not actively hosting content at the time of analysis. The page title reported by passive monitoring reads “Download Zoom,” and the threat classification is listed as brand impersonation targeting the Zoom brand.
This aligns with two AlienVault OTX pulses that reference the domain, indicating that it has been observed in prior threat intel. Gridinsoft assigns a trust score of 0 out of 100, and the domain appears on three known security blocklists. Additional blocklist entries from PhishDestroy, MetaMask, and SEAL confirm that the domain is being actively blocked by multiple protective services. VirusTotal analysis shows that 17 out of 93 scanning engines flagged the domain as malicious, reinforcing the suspicion of fraudulent activity.
The combination of a brand‑specific page title, low trust score, multiple blocklist listings, and detections by reputable scanners suggests a high probability that the domain was used to lure victims into downloading counterfeit Zoom software or to harvest credentials. Defenders should continue to block zoommeetingsinvitees.com at network perimeters, update URL filtering policies, and monitor for any resurgence of activity from the associated IP address or name servers. Because the site is currently offline, any future re‑activation would likely repeat the same impersonation tactics, so continuous vigilance is advised.
Данные сетевой безопасности Registrar context
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| Hagezi Threat Feed | sampaworks.info |
malicious | Sinkholed |
| DNS4EU | sampaworks.info |
malicious | Sinkholed |
Процесс реагирования на угрозы
Статус в публичных блок-листах
Сохранённый снимок
Аналитика доменов
Технические сведенияDNS, SAN в протоколе SSL, временные метки
ICANN OVERSIGHT
Аккредитация и контекст RAA
Аккредитация и контекст RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Анализ VirusTotal
Доказательства и внешние отчеты
PD-20260130-B24CD6 Recipient: abuse@myloc.de Повлиял ли на вас этот сайт?
Если вы ввели учетные данные, личную или платежную информацию или загрузили файл с этого домена, примите немедленные меры. Ниже приведены ресурсы, которые помогут вам сообщить об инциденте и защитить себя.
Сообщите об этом в местные органы власти
Выберите свою страну, чтобы получить официальные контакты по киберпреступности или создать проект жалобы →.
Проверить любой домен
Анализ угроз с использованием сохраненного черного списка, WHOIS, DNS и общедоступных доказательств сканирования.
Сканировать сейчасСообщить о фишинге
Добавляйте подозрительные домены в нашу базу данных угроз — защищайте сообщество
СообщитьПоток оперативных данных об угрозах
Недавние сообщения о фишинге и наблюдаемые изменения доступности
ОтслеживатьБудьте в курсе событий, берегите себя
Отслеживайте актуальные угрозы или оспорьте эту запись, если считаете, что это ложное срабатывание