candidatezoomcall[.]im
Перевірка домену candidatezoomcall.im на фішинг і безпеку
“Zoom Client Update”
candidatezoomcall.im — Контент недоступний (HTTP 502). Уособлення бренду: Microsoft; Тип шахрайства: Brand Impersonation. Зведення доказів: VirusTotal 6/93 (alphaMountain.ai, CRDF, CyRadar, SafeToOpen, SOCRadar); URLQuery 100 det.; URLScan malicious verdict; Spamhaus DBL_PHISH; PhishDestroy score 95/100. Реєстратор: Redacted.
Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.
candidatezoomcall.im was observed hosting a page titled “Zoom Client Update” that purports to target Microsoft users. The domain was registered on 21 February 2026 and resolves to the IPv4 address 89.163.155.33, which belongs to AS24961 (WIIT AG) and is geolocated in Germany. TLS termination is provided by a Google Trust Services certificate issued to “WE1”, indicating the site leveraged Cloudflare’s SSL infrastructure. Network analysis shows the site employed Cloudflare services, including Browser Insights and HTTP/3, consistent with the observed technology fingerprint.
Reputation services flagged the domain: six of ninety‑three VirusTotal scanners raised detections, and the site appears on three external blocklists. It is currently listed as blocked by PhishDestroy, MetaMask, and SEAL, and the overall Gridinsoft trust score is 0 out of 100. The authoritative name servers are ns7.privatedns.vip and ns8.privatedns.vip, both duplicated in the record, a pattern often seen in malicious deployments. The primary malicious behavior is classified as brand impersonation of Microsoft, although the page title references Zoom, suggesting a possible lure combining multiple brand names.
The site is presently offline, limiting immediate observation, and no further content details have been captured. Defenders should add the IP address 89.163.155.33 and the domain to network blocklists, monitor for any re‑registration or similar sub‑domains, and enforce strict email filtering for messages referencing “Zoom Client Update” or Microsoft credential requests. Continuous telemetry from DNS and SSL logs is recommended to detect resurgence of the infrastructure.
Процес реагування на загрози Pipeline
Статус у публічних блоклистах
Технології · 3 identified
Cloudflare Browser Insights is a tool that measures the performance of websites from the perspective of users.
www.cloudflare.com 100% впевненостіCloudflare is a web-infrastructure and website-security company, providing content-delivery-network services, DDoS mitigation, Internet security, and distributed domain-name-server services.
www.cloudflare.com 100% впевненостіHTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org 100% впевненостіАналіз VirusTotal
Архівні докази
Докази та зовнішні звіти
PD-20260124-C15D6A Recipient: abuse@myloc.de Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога