MALICIOUS — CRITICAL
marriott-hiring[.]com
19 of 91 security engines flagged the domain; the latest stored check returned HTTP 200.
- VirusTotal
- 19/91
- Blocklists
- No stored match
- التوفر
- آخر نشاط معروف · HTTP 200
Do not enter credentials, seed phrases, payment details, or personal information on this domain.
Notification and current-status evidence
The sent-report ledger records the first outgoing report at .
The recorded recipient is abuse@name.com.
The latest stored availability evidence still shows the domain reachable; 1 month has elapsed since the first outgoing report.
ICANN RAA §3.18 describes registrar abuse-contact and handling obligations. This section records outgoing timestamps, listed recipients, case identifiers, and later availability. It does not by itself prove receipt, acknowledgement, investigation, remediation, or contractual non-compliance.
Jump to section
marriott-hiring.com — آخر نشاط معروف (HTTP 200). انتحال العلامة التجارية: Marriott; نوع الاحتيال: Credential Phishing. ملخص الأدلة: VirusTotal 19/91 (alphaMountain.ai, BitDefender, Chong Lua Dao, CRDF, CyRadar); URLQuery 2 alerts; URLScan malicious verdict; PhishDestroy score 100/100. مسجّل النطاق: Name.com.
يبقى تحليل PhishDestroy AI المفصل أدناه باللغة الإنجليزية للحفاظ على السجل الجنائي الرقمي الأصلي.
Evidence Digest
marriott-hiring.com is classified critical with an evidence score of 100/100. 19 of 91 security engines flagged the domain. Registered 12 Jun 2026 via Name.com, Inc., hosted on 63.176.8.218 (Amazon.com, Inc., DE). The latest stored check on 9 Aug 2026 returned HTTP 200 and includes a capture. 1 outgoing abuse report is recorded, most recently on 12 Jun 2026.
Stored generated summary (templated)mistral · 25/06/2026
Retained for the record. This text repeats stored detection facts and is not presented as authored analysis.
This domain, marriott-hiring.com, is identified as a credential harvesting phishing campaign targeting job applicants under the guise of Marriott International employment opportunities. The page title, 'Jobs at Marriott International,' mimics legitimate recruitment portals to deceive victims into submitting personal and professional details. No explicit drainer kit signatures were detected, but the infrastructure aligns with common phishing toolchains leveraging static site hosting and analytics tracking to monitor victim interactions.
Infrastructure analysis reveals the domain was registered on June 12, 2026, through Name.com, Inc., and resolves to the IP address 63.176.8.218. Detection metrics indicate 12 out of 95 security vendors on VirusTotal flagged the domain as malicious, while Gridinsoft assigned a trust score of 0/100. The domain appears on a single security blocklist, and Google Safe Browsing (GSB) does not currently list it. Technologies detected include Netlify for hosting, HSTS for enforced encryption, and Google Analytics for traffic monitoring, alongside a Let's Encrypt SSL certificate to lend superficial legitimacy.
As of the latest assessment, marriott-hiring.com has been taken offline, likely due to hosting provider intervention or registrar enforcement. However, the elevated risk persists due to the domain's recent creation date and the potential for infrastructure reuse under similar typosquatting variations. Organizations are advised to monitor for residual DNS caching, block the IP 63.176.8.218 at perimeter defenses, and educate users on verifying recruitment portals through official brand channels. Continuous scanning for related domains registered under the same registrar or IP range is recommended to preempt further abuse.
نطاق تغطية البيانات12 recorded checks
استخبارات أمن الشبكات
مسار الاستجابة للتهديدات Pipeline
حالة قوائم الحظر العامة
لقطة محفوظة
معلومات النطاق
التفاصيل الفنيةDNS، أسماء المجال البديلة (SAN) في بروتوكول SSL، الطوابع الزمنية
ICANN OVERSIGHT
الاعتماد وسياق RAA
الاعتماد وسياق RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
التقنيات · 3 identified
Netlify providers hosting and server-less backend services for web applications and static websites.
www.netlify.com ثقة 100٪HTTP Strict Transport Security (HSTS) informs browsers that the site should only be accessed using HTTPS.
www.rfc-editor.org ثقة 100٪Google Analytics is a free web analytics service that tracks and reports website traffic.
google.com ثقة 100٪تحليل VirusTotal
تحليل أداء الموقع
Google PageSpeed Insights — mobile performance audit of marriott-hiring.com · checked Jun 25, 2026
الأدلة والتقارير الخارجيةIndependent lookups and source reports
PD-20260612-A05FF2 Recipient: abuse@name.com Victim safety and official reportingImmediate actions and verified reporting channels
إذا أدخلت بيانات اعتماد الحساب أو المعلومات الشخصية أو معلومات الدفع أو قمت بتنزيل ملف من هذا النطاق، فاتخذ إجراءً فوريًا. فيما يلي موارد لمساعدتك في الإبلاغ عن الحادث وحماية نفسك.
أبلغ السلطات المحلية
حدد بلدك للحصول على الاتصالات الرسمية المتعلقة بالجرائم الإلكترونية أو إنشاء مسودة شكوى →.