zoom.frash.org
Category: Phishing
- Don't sign in or pay here. Close it. If you typed a password, change it where you normally use it.
- Already visited? Check your device. A free scan shows whether anything was installed.
- Stop the next one. Combo Cleaner's web protection blocks phishing and scam sites before they load.
Combo Cleaner is PCrisk's own anti-malware tool, owned by RCS LT. Free to scan; removing what it finds needs a licence (7-day free trial).
Quttera Web Malware Removal is a paid subscription service. Pricing, plans, and trial availability are set by Quttera. Quttera is operated by Quttera Ltd, an independent third-party company unrelated to RCS LT. PCrisk.com may earn a referral commission when users sign up through this link.
Description of zoom.frash.org
The domain zoom.frash.org appears to present itself as a Zoom-related meeting or conferencing page. The screenshot shows a loading screen with the message "We're setting up your meeting...", and the scanned resources reference Zoom branding assets along with Microsoft-themed image files. Based on the visible content and linked files, the page may be attempting to imitate a video-meeting invitation or setup workflow.
This site does not appear to be an official Zoom domain. Instead, it is hosted as a subdomain of frash.org, which is not commonly associated with Zoom's known web infrastructure. The presence of meeting-themed paths such as invite, install-guide, download, and zoom.php suggests the page may be designed to direct visitors through a fake meeting setup or software download process rather than provide a legitimate conferencing service.
Safety Assessment for zoom.frash.org
Multiple scan signals indicate elevated risk at the time of this scan. The domain was flagged by 10 out of 89 security engines, with several classifying it as phishing or malicious. Malware scanning also reported malicious findings, including flagged files and links on the site, and one referenced external domain was also marked suspicious. In addition, the page uses branding elements associated with Zoom while operating from an unrelated subdomain, which may indicate an attempt to resemble a trusted service.
There are further cautionary indicators in the domain profile and infrastructure. The domain is relatively new at about 165 days old, has no established traffic ranking, and includes downloadable or installation-related paths that can be associated with deceptive setup flows. The domain's IP address is also listed on one mail-reputation blocklist, which is a weaker signal than direct phishing detections but still worth noting. Although one major threat database reported the site as clean, the broader scan consensus and the page's branding pattern point in a more concerning direction.
Based on these findings, this website may pose potential risks to visitors.
Technical Description
The site uses a valid Let's Encrypt SSL certificate, which means the connection can be encrypted in transit, but HTTPS alone does not indicate legitimacy. It is hosted on an AWS EC2 IP address in Columbus, United States, with Cloudflare serving as the registrar and Cloudflare nameservers configured. The web server software was not identified from the available scan data.
From a security posture perspective, the domain is DNSSEC unsigned, relatively new, and hosted on generic cloud infrastructure that can be quickly provisioned. The scan also identified multiple suspicious internal resources, including download.php, install-guide.php, and zoom.php, as well as references to a separate Zoom-themed external domain. These technical indicators may be consistent with a short-lived phishing or malware-delivery setup.
Share your experience with this website. Was it safe? Did you encounter any issues?