zimbrasoft[.]com[.]ua
“200 OK”
证据摘要
On August 01, 2026, zimbrasoft.com.ua was assessed as an active generic phishing threat with a high risk profile. The domain was initially registered on January 20, 2026, through ТОВ "Сервіс Онлайн" and currently resolves to IP address 193.238.152.66. Infrastructure analysis confirms use of Cloudflare-provided nameservers, specifically armando.ns.cloudflare.com and keira.ns.cloudflare.com, which may indicate traffic obfuscation or defensive measures against takedown efforts. The domain remains active and is present on at least one recognized security blocklist, including PhishDestroy, signifying intent or evidence of phishing operations.
VirusTotal reports that 20 out of 91 reputable security vendors have flagged this domain as malicious, strengthening the case for its association with phishing activity. The domain’s inclusion on blocklists and multiple detection engines suggests ongoing risk to users, though the specific content and targeted entities have not been directly analysed or confirmed in this report. No further details regarding SSL certificate status, HTTP response, or page title are available; thus, defenders should treat the domain as high-risk based on detected threat indicators from reputable sources.
Immediate blocking at network and endpoint levels is advised, and ongoing monitoring should be maintained for associated infrastructure or similar domains registered under the same provider. There is insufficient evidence to determine the exact nature of the phishing scheme or any brand targeting; therefore, all interactions should be considered unsafe. Further evidence should be collected if defenders encounter related domains or suspicious activity linked to the same IP, registrar, or nameservers.
Data Coverage
网络安全情报
威胁响应 Pipeline
阻止列表覆盖
监控中的外部数据源 10 个 · 已存快照 2026年8月13日
检测时间线
-
首次记录
首次存储值:可访问
VirusTotal 分析
存档证据
网站性能分析
Google PageSpeed Insights — mobile performance audit of zimbrasoft.com.ua · checked Aug 1, 2026
您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。
检查任意域名
使用存储的阻止列表、WHOIS、DNS 和公共扫描证据进行威胁分析
立即扫描举报网络钓鱼
将可疑域名提交至我们的威胁数据库——保护社区
报告实时威胁动态
最近的网络钓鱼报告和观察到的可用性变化
监控