dpdbitkouyem-rlsaq0in-mhd0c9gt[.]s3[.]amazonaws[.]com
dpdbitkouyem-rlsaq0in-mhd0c9gt.s3.amazonaws.com — Nicht bestätigt. Markenidentität: Amazon; Betrugstyp: Brand Impersonation. Zusammenfassung der Beweislage: VirusTotal 6/91 (alphaMountain.ai, BitDefender, Fortinet, G-Data, Gridinsoft); URLQuery 5 alerts; Google Safe Browsing flagged; PhishDestroy score 98/100. Registrar: MarkMonitor.
Die ausführliche Analyse von PhishDestroy AI bleibt auf Englisch, damit der ursprüngliche forensische Bericht unverändert bleibt.
This domain is flagged as a high-risk brand impersonation targeting Amazon. It was created on May 1, 2026, and remains active as of July 12, 2026. The domain resolves to IP 16.15.191.167, hosted on AWS EC2 in the US (us-east-1). SSL certificate details show it uses an Amazon-branded certificate (Amazon RSA 2048 M04), which is a common tactic to deceive users. Google Safe Browsing flags the domain for SOCIAL_ENGINEERING, and 10 out of 91 security vendors on VirusTotal detect it as malicious. It appears on one security blocklist and is blocked by PhishDestroy. The HTTP response is a 403 Forbidden, indicating restricted access. Infrastructure analysis reveals nameservers are all on awsdns-37.org, awsdns-16.co.uk, awsdns-03.com, and awsdns-01.net, consistent with AWS Route 53. The domain is registered through MarkMonitor Inc., a legitimate registrar, but the trust score from Gridinsoft is 0 out of 100. Defenders should block this domain at the network level, monitor for any related subdomains or IP changes, and educate users not to trust emails or links referencing Amazon that lead to this domain. The exact page content is unknown, but the combination of brand impersonation, social engineering flags, and low trust score confirms this is an active threat. No additional scam category or kit details are available in the intelligence provided.
Erkenntnisse zur Netzwerksicherheit
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| DNS4EU | joystay.in |
malicious | Sinkholed |
| Hagezi Threat Feed | joystay.in |
malicious | Sinkholed |
| Quad9 DNS | joystay.in |
malicious | Sinkholed |
| OpenDNS | joystay.in |
phishing | Phishing Block |
| Cloudflare DNS | joystay.in |
malicious | Sinkholed |
Pipeline zur Reaktion auf Sicherheitsbedrohungen
Status der öffentlichen Sperrliste
Gespeicherte Aufnahme
Domain-Intelligenz
Technische DetailsDNS, SSL-SANs, Zeitstempel
VirusTotal-Analyse
Nachweise und externe Berichte
Wurden Sie von dieser Website betroffen?
Wenn Sie Kontoanmeldeinformationen, persönliche oder Zahlungsinformationen eingegeben oder eine Datei von dieser Domain heruntergeladen haben, ergreifen Sie sofort Maßnahmen. Nachfolgend finden Sie Ressourcen, die Ihnen helfen, den Vorfall zu melden und sich zu schützen.
Melden Sie sich bei Ihren örtlichen Behörden
Wählen Sie Ihr Land aus, um Offizielle Kontakte im Bereich Cyberkriminalität oder einen Beschwerdeentwurf erstellen → zu erhalten.
Jede beliebige Domain prüfen
Bedrohungsanalyse anhand gespeicherter Blocklisten, WHOIS, DNS und öffentlicher Scan-Beweise
Jetzt scannenPhishing melden
Melden Sie verdächtige Domains an unsere Bedrohungsdatenbank – schützen Sie die Community
MeldenEchtzeit-Bedrohungsfeed
Aktuelle Phishing-Meldungen und beobachtete Verfügbarkeitsänderungen
ÜberwachenBleiben Sie auf dem Laufenden, bleiben Sie sicher
Beobachten Sie aktuelle Bedrohungen oder legen Sie Widerspruch gegen diesen Eintrag ein, wenn Sie der Meinung sind, dass es sich um einen Fehlalarm handelt