# PhishDestroy threat dossier — s3-eu-west-1.amazonaws.com ================================================================ Fetched: 2026-07-28 14:19:21 UTC Canonical: https://phishdestroy.io/domain/s3-eu-west-1.amazonaws.com/ ## VERDICT ---------------------------------------------------------------- ACTIVE THREAT — multiple warning signs Composite threat score: 46/100 (PhishDestroy scoring — see methodology below) ## DETECTION EVIDENCE ---------------------------------------------------------------- VirusTotal: 1/91 security vendors flagged this domain Flagging vendors: AILabs (MONITORAPP) Public blocklists: listed on 1 independent blocklist ## INFRASTRUCTURE ---------------------------------------------------------------- IP address: 3.5.74.62 (IE, Dublin) ASN: AS16509 Amazon.com, Inc. Hosting org: AWS EC2 (eu-west-1) Registrar: MarkMonitor Inc. Nameservers: ["ns-1321.awsdns-37.org", "ns-1670.awsdns-16.co.uk", "ns-27.awsdns-03.com", "ns-967.awsdns-56.net"] Page title: Cloud Object Storage – Amazon S3 – Amazon Web Services HTTP response: 307 ## TLS CERTIFICATE ---------------------------------------------------------------- Issuer: Amazon / Amazon RSA 2048 M04 Expires: 2026-11-06 Status: INVALID chain Fingerprint: c50eb83f833b91929a4bdbbdb3680b8c7a88836963bdda8153682f31449d542e Subject Alternative Names (related infrastructure — often same operator): - s3-control.dualstack.eu-west-1.amazonaws.com - s3-control.eu-west-1.amazonaws.com - s3-deprecated.eu-west-1.amazonaws.com - s3-external-3.amazonaws.com - s3.amazonaws.com - s3.dualstack.eu-west-1.amazonaws.com - s3.eu-west-1.amazonaws.com ## ABUSE-REPORT HISTORY (evidence of registrar non-response) ---------------------------------------------------------------- Status: pending notification queue. No abuse reports filed yet — this domain is waiting for the next cycle of our automated abuse-reporter. ## TIMELINE ---------------------------------------------------------------- First detected: 2026-07-28 04:03:08 UTC (by PhishDestroy tracker) Last verified: 2026-07-28 12:56:21 UTC Current status: ACTIVE / observable ## ANALYST NARRATIVE ---------------------------------------------------------------- [Generated: 2026-07-28 04:06:26 UTC — narrative may predate facts above. Treat fields in TIMELINE / DETECTION EVIDENCE / INFRASTRUCTURE as authoritative if they differ from the prose below.] s3-eu-west-1.amazonaws.com – Phishing Campaign Detected The domain s3-eu-west-1.amazonaws.com is currently flagged as a high‑risk phishing campaign according to the July 28, 2026 assessment. Registration data shows the domain was created through MarkMonitor Inc., a registrar commonly used for legitimate cloud services, which does not by itself indicate malicious intent. Infrastructure analysis reveals that the domain resolves to four Amazon Route 53 name servers: ns-1321.awsdns-37.org, ns-1670.awsdns-16.co.uk, ns-27.awsdns-03.com, and an additional entry truncated in the source data. The presence of these authoritative name servers is consistent with the Amazon S3 hosting model, but does not preclude abuse. VirusTotal reports a single positive detection out of 91 scanned security vendors, indicating that at least one vendor has identified the domain as malicious. The domain is listed on one public security blocklist and has been explicitly blocked by the PhishDestroy service, reinforcing the view that it is being used for phishing. HTTP probing returns a 307 temporary redirect response, a pattern often observed in malicious redirection chains designed to evade simple URL filters. The domain remains active at the time of analysis, and no additional evidence such as page titles, SSL certificate details, or Safe Browsing alerts is presently available. Given the limited but concrete indicators—single vendor detection, blocklist presence, redirection behavior, and active status—defenders should treat any traffic to this domain as suspicious. Recommended mitigations include adding the domain to network deny lists, enforcing URL filtering rules that block known phishing hosts, and monitoring for any outbound connections from internal assets to the associated IP ranges. Continuous re‑evaluation is advised, as further threat intelligence (e.g., additional vendor detections, SSL fingerprinting, or content analysis) may emerge and refine the risk posture. ## EVIDENCE HASHES ---------------------------------------------------------------- TLS cert SHA-256: c50eb83f833b91929a4bdbbdb3680b8c7a88836963bdda8153682f31449d542e ## SCORING METHODOLOGY ---------------------------------------------------------------- Composite score is NOT derived from VirusTotal alone. PhishDestroy aggregates: - VirusTotal positive ratio - Public blocklist consensus (MetaMask, ScamSniffer, OpenPhish, PhishTank, URLhaus, CryptoFirewall, SEAL, Polkadot, Enkrypt, Phishunt, DiscordPhishing, PhishingDB) - Cloaking detection (HTTP 666 or rendering delta between bot and real visitor) - DNS-filter consensus (Quad9, CleanBrowsing, NextDNS, AdGuard, Cloudflare, etc.) - AlienVault OTX pulses + Cloudflare Radar + Google Safe Browsing - URLScan / URLQuery verdicts - Brand-impersonation heuristics (DOM analysis of forms, logos, wording) - Known phishing-kit fingerprinting (favicon hash, JS obfuscation signatures) - Wallet-drainer family classification (Angel, MS, Rainbow, Pink, Inferno, ...) - Free-TLS vs paid-cert ratio (throwaway infrastructure signal) - Registrar/hosting abuse history (this registrar's track record) - Human researcher sign-off (operator takedown team) A domain present in our database is ALREADY flagged. A low VT count by itself does NOT mean the domain is safe — new scam domains routinely show 0/95 VT for their first 7–30 days while actively draining wallets. Always cross-reference the composite score and the individual indicators above, not just VT. ## CORRECTIONS / APPEALS ---------------------------------------------------------------- Full HTML report: https://phishdestroy.io/domain/s3-eu-west-1.amazonaws.com/ JSON API: https://api.destroy.tools/v1/check?domain=s3-eu-west-1.amazonaws.com Appeal a flag: https://phishdestroy.io/appeals/ (responded to within 48 hours, FP rate <0.01%) Submit a report: https://t.me/PhishDestroy_bot About PhishDestroy: independent open-source threat-intelligence platform. Tracked: 211,155 domains (85,595 alive under monitoring, 124,530 confirmed takedowns/dead). Site: https://phishdestroy.io