usstampdepot[.]com
Phishing- und Sicherheitsprüfung für usstampdepot.com
“stamps sale forever stamps authorized factory stores”
usstampdepot.com — Inhalt nicht verfügbar (HTTP 502). Markenidentität: Google; Betrugstyp: Generic Phishing. Zusammenfassung der Beweislage: VirusTotal 16/95 (alphaMountain.ai, BitDefender, Cluster25, CRDF, CyRadar); URLQuery 100 det.; URLScan malicious verdict; PhishDestroy score 95/100. Registrar: NameSilo.
Die ausführliche Analyse von PhishDestroy AI bleibt auf Englisch, damit der ursprüngliche forensische Bericht unverändert bleibt.
The domain usstampdepot.com was created on October 08, 2025 and is currently listed as offline. Infrastructure analysis shows the domain resolves to the IP address 104.18.8.146, which belongs to the Cloudflare network (AS13335) and is geolocated in the United States. No SSL certificate is associated with the host, indicating that secure HTTPS connections are not available. The domain is registered through NameSilo, LLC and uses the DNS Owl name servers ns1.dnsowl.com, ns2.dnsowl.com, and ns3.dnsowl.com.
Threat intelligence flags the site as a brand impersonation of Google, with the page title "stamps sale forever stamps authorized factory stores" providing no direct evidence of Google branding but confirming the presence of a commercial‑type title. The site has been blocked by the PhishDestroy feed and appears on one external security blocklist. Gridinsoft assigns a trust score of 0 out of 100, reflecting a high likelihood of malicious intent.
VirusTotal analysis records that 16 of 95 scanning engines flagged the domain, reinforcing the suspicion of malicious activity. Given the lack of SSL, the offline status, and the presence of multiple detections, defenders should continue to block the domain at perimeter and DNS layers, monitor for any re‑hosting attempts, and consider adding the IP address to threat‑intel feeds. Ongoing vigilance is advised for any new domains that resolve to the same Cloudflare edge nodes and exhibit similar registration patterns, as threat actors frequently recycle infrastructure for brand‑impersonation campaigns.
Erkenntnisse zur Netzwerksicherheit Registrar context
Pipeline zur Reaktion auf Sicherheitsbedrohungen
Status der öffentlichen Sperrliste
Gespeicherte Aufnahme
Domain-Intelligenz
Technische DetailsDNS, SSL-SANs, Zeitstempel
ICANN OVERSIGHT
Akkreditierung und RAA-Kontext
Akkreditierung und RAA-Kontext
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
VirusTotal-Analyse
Archivierte Beweise
Nachweise und externe Berichte
Wurden Sie von dieser Website betroffen?
Wenn Sie Kontoanmeldeinformationen, persönliche oder Zahlungsinformationen eingegeben oder eine Datei von dieser Domain heruntergeladen haben, ergreifen Sie sofort Maßnahmen. Nachfolgend finden Sie Ressourcen, die Ihnen helfen, den Vorfall zu melden und sich zu schützen.
Melden Sie sich bei Ihren örtlichen Behörden
Wählen Sie Ihr Land aus, um Offizielle Kontakte im Bereich Cyberkriminalität oder einen Beschwerdeentwurf erstellen → zu erhalten.
Jede beliebige Domain prüfen
Bedrohungsanalyse anhand gespeicherter Blocklisten, WHOIS, DNS und öffentlicher Scan-Beweise
Jetzt scannenPhishing melden
Melden Sie verdächtige Domains an unsere Bedrohungsdatenbank – schützen Sie die Community
MeldenEchtzeit-Bedrohungsfeed
Aktuelle Phishing-Meldungen und beobachtete Verfügbarkeitsänderungen
ÜberwachenBleiben Sie auf dem Laufenden, bleiben Sie sicher
Beobachten Sie aktuelle Bedrohungen oder legen Sie Widerspruch gegen diesen Eintrag ein, wenn Sie der Meinung sind, dass es sich um einen Fehlalarm handelt