notification[.]investigation[.]pics
“The Intertwined Destinies: Amazon & The Amazon”
notification.investigation.pics — المحتوى غير متوفر (HTTP 502). انتحال العلامة التجارية: Amazon; نوع الاحتيال: Credential Phishing. ملخص الأدلة: VirusTotal 15/95 (ADMINUSLabs, Criminal IP, alphaMountain.ai, BitDefender, CyRadar); PhishDestroy score 95/100. مسجّل النطاق: NameSilo.
يبقى تحليل PhishDestroy AI المفصل أدناه باللغة الإنجليزية للحفاظ على السجل الجنائي الرقمي الأصلي.
Analysis of notification.investigation.pics, observed on July 23 2026, shows a credential‑phishing site that masquerades as Amazon. The domain was registered on 16 October 2025 through NameSilo, LLC and uses the dnsowl.com name server set (ns1, ns2, ns3). It resolves to 172.81.133.39, an address owned by DataWagon LLC (ASN 27176) located in the United States. No TLS certificate is presented, indicating the site operates over plain HTTP.
VirusTotal records indicate that 15 of 95 scanned security engines flagged the domain, confirming malicious intent. Independent scoring by Gridinsoft assigns a trust score of 0 out of 100, and the domain appears on a single public blocklist, where it is listed by PhishDestroy. The page title returned by the server is “The Intertwined Destinies: Amazon & The Amazon,” reinforcing the Amazon impersonation claim. The site is currently offline, but the infrastructure details remain useful for detection.
Uncertainty remains regarding the exact phishing kit or any additional payloads because the content has not been captured. Defenders should block the resolved IP address and the domain at DNS and proxy layers, monitor for traffic to the dnsowl.com name servers, and add the domain to local blocklists. Continued observation of the AS27176 range is recommended, as other malicious actors may reuse the same hosting provider. Indicators of compromise include the domain name, registration date, name servers, IP address, and the observed page title.
استخبارات أمن الشبكات Registrar context
مسار الاستجابة للتهديدات Pipeline
حالة قوائم الحظر العامة
لقطة محفوظة
معلومات النطاق
التفاصيل الفنيةDNS، أسماء المجال البديلة (SAN) في بروتوكول SSL، الطوابع الزمنية
ICANN OVERSIGHT
Registration: investigation.pics
الاعتماد وسياق RAA
الاعتماد وسياق RAA
Registrar accreditation and DNS abuse obligations
For the registrable domain investigation.pics behind this subdomain, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
تحليل VirusTotal
الأدلة والتقارير الخارجية
هل تأثرت بهذا الموقع؟
إذا أدخلت بيانات اعتماد الحساب أو المعلومات الشخصية أو معلومات الدفع أو قمت بتنزيل ملف من هذا النطاق، فاتخذ إجراءً فوريًا. فيما يلي موارد لمساعدتك في الإبلاغ عن الحادث وحماية نفسك.
أبلغ السلطات المحلية
حدد بلدك للحصول على الاتصالات الرسمية المتعلقة بالجرائم الإلكترونية أو إنشاء مسودة شكوى →.
تحقق من أي نطاق
تحليل التهديدات باستخدام قائمة الحظر المخزنة، وWHOIS، وDNS، وأدلة الفحص العامة
امسح الآنالإبلاغ عن محاولة تصيد احتيالي
أرسل النطاقات المشبوهة إلى قاعدة بيانات التهديدات الخاصة بنا — ساهم في حماية المجتمع
إبلاغتحديثات فورية حول التهديدات
تقارير التصيد الاحتيالي الأخيرة وتغييرات التوفر الملحوظة
مراقبةابقَ على اطلاع، وابقَ آمنًا
راقب التهديدات في الوقت الفعلي أو اعترض على هذا الإدراج إذا كنت تعتقد أنه إنذار كاذب