Skip to security report
⚠️
This domain has been flagged as malicious
Security engines reporting a detection: 17. Exercise extreme caution — do not enter credentials or personal information.
Domain security and threat intelligence

greetings[.]pictures

“404 - Quick Tip | Cofense”

Threat verdict Critical 98/100 evidence score
Availability Unverified Current reachability is unverified
VirusTotal detections: 17/91
OTX: 13 refs Jun 7, 2026
Evidence Summary
CRITICAL
Ref
0821A091
Score
98/100

The domain greetings.pictures is currently listed as active and assigned an elevated risk rating. It has been blocked by the PhishDestroy mitigation service and is present on a single external security blocklist. VirusTotal analysis shows that 17 of 91 scanned security engines returned a malicious verdict for the domain, indicating a consensus of concern among a subset of scanners.

No additional telemetry such as registrar data, IP address, hosting ASN, SSL certificate details, HTTP response codes, safe‑browsing status, or page title has been disclosed in the available intelligence. Consequently, the full scope of the underlying infrastructure remains indeterminate. The observed detections align with the generic phishing classification supplied in the report metadata, suggesting that the site is likely being used to harvest credentials or other sensitive information.

Defenders are advised to enforce network‑level deny rules for greetings.pictures, incorporate the domain into endpoint and web‑gateway blocklists, and continue to monitor threat‑intel feeds for any emerging indicators such as resolved IP addresses or associated payload hashes. Ongoing collection of passive DNS and WHOIS records should be prioritized to refine attribution and to support any takedown efforts.

VirusTotal
VirusTotal
17 det.
OTX references
TLS Certificate
Let's Encrypt 16d
Observed status
Unverified
PhishDestroy
DestroyList
Listed
Data coverage VirusTotal 17 / 91 URLQuery not checked PhishStats not checked OTX 13 community references CF Radar scan completed URLScan capture not submitted URLScan verdict verdict unavailable DNS blocks not checked TLS valid certificate, 16d WHOIS not parsed Screenshot not captured Redirect chain not probed

Threat Response Pipeline

Discovery
Checks
Reports
Availability
10/12

Public Blocklist Status

Domain Intelligence

Domain
Server / ASN AS16509 Amazon.com, Inc.
IP Reputation abuse score 0/100 0 reports checked Jul 30, 2026
IP Address 13.210.89.195 AU
GeoAU Sydney, AU
NetworkAS16509 · AWS EC2 (ap-southeast-2)
Elapsed Since First Report 52 days
What we count Raw elapsed time since the first stored abuse report. It is not a registrar response-time measurement. Latest observed status: Unverified.
What each report contains Stored outgoing-report records may reference evidence available at the time, such as vendor verdicts, registration data, hosting details, classifications, or screenshots. This page does not infer the exact payload delivered, receipt, acknowledgement, or action by a recipient.
Technical detailsDNS, SSL SANs, timestamps
First DetectedJun 7, 2026
Submitted URLhttp://greetings.pictures/secure/training/6422c2/8c5781c2-7b1e-4035-b1d7-990e269e5380
Nameserversns-1412.awsdns-48.org
MX Records10 mx0.us.cf-ops.net
TLS Fingerprint
TLS Observationvalid from May 16, 2026scanned Jul 30, 2026
Favicon Hash
ICANN OVERSIGHT

Accreditation and RAA context

Registrar accreditation and DNS abuse obligations

For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.

Accreditation is a contract, not a safety certification.

RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.

Accountability draft Nothing is sent automatically.
Technologies · 1 identified
HSTS
Security

HTTP Strict Transport Security (HSTS) informs browsers that the site should only be accessed using HTTPS.

www.rfc-editor.org 100% confidence
Detected via Cloudflare Radar · Wappalyzer engine
Report This Domain Submit evidence & help protect others

VirusTotal Analysis

17 / 91 security vendors flagged this domain
View on VT
Last analyzed
ADMINUSLabs
alphaMountain.ai
BitDefender
Chong Lua Dao
Cluster25
CRDF
ESET
Forcepoint ThreatSeeker
Fortinet
G-Data
Gridinsoft
Kaspersky
Lionic
MalwareURL
SOCRadar
Sophos
VIPRE
Site Performance Analysis

Google PageSpeed Insights — mobile performance audit of greetings.pictures · checked Jul 29, 2026

94
Good
Performance
FCP
0.76s
First Contentful Paint
LCP
1.8s
Largest Contentful Paint
CLS
0.142
Cumulative Layout Shift
TBT
0ms
Total Blocking Time
SI
1.83s
Speed Index
Powered by Google PageSpeed Insights · Mobile strategy · Scores: 90-100 Good 50-89 Needs Work 0-49 Poor
Site Configuration Analysis
Stored observations are retained with their original collection time.
robots.txt Present · HTTP 200
Valid robots.txt; no Disallow/Allow paths were extracted.

Evidence & External Reports

Were You Affected by This Site?

If credentials were compromised, report immediately. Do not engage with recovery scammers.

If credentials, payment data, or files were exposed, report the incident immediately. Change affected passwords, revoke active sessions, and scan the device.

Europol
Find the official reporting channel for your EU country
National police directory
Beware of recovery scammers! Recovery scammers may pose as investigators, lawyers, or tracing services. Do not pay upfront fees or disclose credentials. Learn more about recovery fraud →

Report to Your Local Authorities

Select your country to get official cybercrime contacts, or create a complaint draft →.

97-country directory
Template-based draft • optional AI wording assistance requires separate consent Review and submit it yourself

Check Any Domain

Threat analysis using stored blocklist, WHOIS, DNS, and public scan evidence

Scan Now

Report Phishing

Submit suspicious domains to our threat database — protect the community

Report

Live Threat Feed

Recent phishing reports and observed availability changes

Monitor

Stay Informed, Stay Safe

Monitor live threats or contest this listing if you believe it's a false positive

Live Threat Feed Appeal This Listing
HTML · IFRAME

Embed This Report

Share this threat intelligence on your website or blog

embed.html
<iframe
  src="https://phishdestroy.io/embed/domain/greetings.pictures"
  title="PhishDestroy threat report for greetings.pictures"
  width="100%" height="320"
  loading="lazy"
  referrerpolicy="no-referrer"
  sandbox="allow-same-origin allow-popups allow-popups-to-escape-sandbox"
  style="border:0;border-radius:12px;max-width:100%"
></iframe>

A Very Sincere Thank-You Note

Satirical draft generator

Recipient
Fee context

Satirical draft. Fee figures are estimates; exact attribution to this domain is not claimed.