zoommeetingsinvitees[.]com
“Download Zoom”
Kanıt özeti
The domain zoommeetingsinvitees.com was registered on February 21 2026 through NameSilo, LLC. DNS resolution points to the IPv4 address 89.163.155.33, which is announced by AS24961 (WIIT AG) and geolocated to Germany. The authoritative name servers are ns7.privatedns.vip and ns8.privatedns.vip, both of which are commonly used by malicious infrastructure. No TLS certificate is presented, indicating the site is served only over HTTP, which further reduces trust. The HTTP response currently returns an offline status, confirming that the site is not actively hosting content at the time of analysis. The page title reported by passive monitoring reads “Download Zoom,” and the threat classification is listed as brand impersonation targeting the Zoom brand.
This aligns with two AlienVault OTX pulses that reference the domain, indicating that it has been observed in prior threat intel. Gridinsoft assigns a trust score of 0 out of 100, and the domain appears on three known security blocklists. Additional blocklist entries from PhishDestroy, MetaMask, and SEAL confirm that the domain is being actively blocked by multiple protective services. VirusTotal analysis shows that 17 out of 93 scanning engines flagged the domain as malicious, reinforcing the suspicion of fraudulent activity.
The combination of a brand‑specific page title, low trust score, multiple blocklist listings, and detections by reputable scanners suggests a high probability that the domain was used to lure victims into downloading counterfeit Zoom software or to harvest credentials. Defenders should continue to block zoommeetingsinvitees.com at network perimeters, update URL filtering policies, and monitor for any resurgence of activity from the associated IP address or name servers. Because the site is currently offline, any future re‑activation would likely repeat the same impersonation tactics, so continuous vigilance is advised.
Gönderilen kanıt anlık görüntüsü
- Gönderildi
- Kayıt defteri kayıtları
- 1
- Vaka kimliği
PD-20260130-B24CD6- Yakalanan sayfa başlığı
- Download Zoom
- PDF belgesi
- PDF kanıtı
Hukuki dayanak
Kanıtın tam metni
Acceptable Use Policy: The domain zoommeetingsinvitees.com is engaged in phishing activities, which are explicitly prohibited under your AUP. This domain is designed to deceive users into providing sensitive information under the guise of legitimate Zoom meeting invitations.
Terms of Service: The continued operation of this domain constitutes a violation of your TOS, which reserves the right to suspend or terminate services for any activities involving fraud or deception.
Applicable Laws (US):
Computer Fraud and Abuse Act (18 U.S.C. § 1030): This federal law prohibits unauthorized access to computers and the fraudulent use of information obtained from such access, which applies to phishing schemes.
Wire Fraud (18 U.S.C. § 1343): This statute criminalizes schemes to defraud individuals or entities using electronic communications, including phishing activities that aim to mislead victims for financial gain.
CAN-SPAM Act (15 U.S.C. § 7701): This law regulates commercial email and prohibits deceptive practices in electronic communications, which includes phishing emails.
Regulatory Note: Failure to take prompt action against this domain may expose your organization to liability under applicable laws and regulations. Continued non-compliance could result in regulatory scrutiny and potential penalties.
Data Coverage
Ağ Güvenliği İstihbaratı
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| Hagezi Threat Feed | sampaworks.info |
malicious | Sinkholed |
| DNS4EU | sampaworks.info |
malicious | Sinkholed |
Tehdit Müdahale Pipeline
Engelleme listesi kapsamı
10 izlenen harici kaynak · kayıtlı anlık görüntü 12.08.2026
Tespit zaman çizelgesi
-
Cloudflare Radar
Cloudflare Radar taraması kaydedildi · Taramayı aç
Kaydedilen görüntü
Etki Alanı Analizi
Teknik ayrıntılarDNS, TLS adları ve zaman damgaları
ICANN OVERSIGHT
Akreditasyon ve RAA bağlamı
Akreditasyon ve RAA bağlamı
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
VirusTotal Analizi
Bu Siteden Etkilendiniz mi?
Hesap kimlik bilgilerini, kişisel bilgileri veya ödeme bilgilerini girdiyseniz ya da bu alan adından bir dosya indirdiyseniz hemen harekete geçin. Aşağıda olayı bildirmenize ve kendinizi korumanıza yardımcı olacak kaynaklar bulunmaktadır.
Yerel Yetkililere Bildirin
resmi siber suç iletişim bilgileri veya şikayet taslağı oluştur → almak için ülkenizi seçin.
Herhangi Bir Alan Adını Kontrol Et
Saklanan engelleme listesi, WHOIS, DNS ve genel tarama kanıtlarını kullanarak tehdit analizi
Şimdi TaraOltalama Olayını Bildir
Şüpheli alan adlarını tehdit veritabanımıza bildirin — topluluğu koruyun
BildirCanlı Tehdit Akışı
Son kimlik avı raporları ve gözlemlenen kullanılabilirlik değişiklikleri
İzleGelişmelerden Haberdar Olun, Güvende Kalın
Canlı tehditleri izleyin veya bunun yanlış bir uyarı olduğunu düşünüyorsanız bu kayda itiraz edin