Analysis of the domain webozip.in indicates that it is currently classified as a high‑risk generic phishing site. The domain was registered on 2022-03-09 through the registrar WeboZip Media and continues to resolve to the IPv4 address 103.211.202.64. Its authoritative name servers are carioca.ns.cloudflare.com and skip.ns.cloudflare.com, both belonging to Cloudflare’s DNS infrastructure. Threat intelligence platforms have listed the domain on one security blocklist, and it is explicitly blocked by the PhishDestroy feed, confirming that defensive operators are already treating it as malicious. VirusTotal reports that six of ninety‑one scanning engines have flagged the domain, providing independent vendor corroboration of its suspicious nature.
No additional public reputation scores, SSL certificate details, or HTTP response codes are available in the supplied data set. The available evidence does not disclose the specific landing page content, page title, or any observed brand impersonation, so the exact phishing lure remains undefined. Likewise, there is no disclosed information about the hosting ASN, geographic location of the IP address, or any associated malware kits. Consequently, the precise operational scope of the campaign—such as targeted victims or credential‑stealing mechanisms—cannot be determined from the current dataset.
Defenders should continue to block webozip.in at network perimeter devices, proxy filters, and endpoint protection solutions. Monitoring of DNS queries for the domain and its associated Cloudflare name servers is advised, as well as the inclusion of the IP address 103.211.202.64 in threat‑intel feeds. Incident response teams should treat any traffic to the domain as malicious and isolate affected hosts for forensic analysis. Ongoing observation of VirusTotal and other vendor feeds is recommended to capture any changes in detection rates or additional indicators of compromise.