amexofficial[.]com
“404 Not Found”
Evidence Summary
Analysis of amexofficial.com indicates that the domain was created on February 21, 2026 and is currently taken offline. The site returns a HTTP 404 Not Found page title, suggesting that any malicious landing page has been removed or disabled. Infrastructure data shows the domain resolves to IP address 188.114.97.3, which belongs to AS13335 Cloudflare, Inc. and is geolocated in the United States. The SSL certificate presented for the host is identified as WE1, but no further certificate details are available.
Threat intelligence records list the domain on a single security blocklist and note that it has been blocked by the PhishDestroy service. VirusTotal scans report that four out of ninety-three security vendors flagged the domain, confirming the presence of malicious activity consistent with a generic phishing campaign. The limited detection count and the solitary blocklist entry suggest that the malicious infrastructure may have been short-lived or that detection coverage is still expanding. Uncertainty remains regarding the specific phishing kit, payload, or targeted brand beyond the generic classification, as no additional content or page analysis is available.
Defenders should continue to monitor DNS queries for amexofficial.com and the associated IP address, enforce outbound filtering to block connections to the resolved IP, and ensure that any residual phishing indicators are removed from internal threat feeds. Organizations using email or web security gateways should add the domain to blocklists and consider updating URL reputation services to reflect the recent detection activity. Ongoing surveillance of Cloudflare‑hosted IP ranges for similar short‑lived phishing domains is recommended to capture emerging threats promptly.
Data Coverage
Threat Response Pipeline
Blocklist coverage
10 monitored external feeds · stored snapshot Aug 12, 2026
10 monitored external feeds No match
VirusTotal Analysis
Were You Affected by This Site?
If credentials, payment data, or files were exposed, report the incident immediately. Change affected passwords, revoke active sessions, and scan the device.
Report to Your Local Authorities
Select your country to get official cybercrime contacts, or create a complaint draft →.
Check Any Domain
Threat analysis using stored blocklist, WHOIS, DNS, and public scan evidence
Scan NowReport Phishing
Submit suspicious domains to our threat database — protect the community
ReportLive Threat Feed
Recent phishing reports and observed availability changes
MonitorStay Informed, Stay Safe
Monitor live threats or contest this listing if you believe it's a false positive