yamzoza-north-007-amazon[.]s3[.]us-east-1[.]amazonaws[.]com
yamzoza-north-007-amazon.s3.us-east-1.amazonaws.com — Belum terverifikasi. Peniruan identitas merek: Amazon; Jenis penipuan: Brand Impersonation. Ringkasan bukti: VirusTotal 9/91 (ADMINUSLabs, alphaMountain.ai, BitDefender, Fortinet, G-Data); URLQuery 1 alert; Google Safe Browsing flagged; PhishDestroy score 98/100. Registrar: MarkMonitor.
Analisis terperinci PhishDestroy AI di bawah tetap berbahasa Inggris untuk menjaga catatan forensik asli.
This domain, yamzoza-north-007-amazon.s3.us-east-1.amazonaws.com, is identified as a generic phishing threat designed to harvest user credentials. Infrastructure analysis reveals the domain mimics legitimate cloud storage endpoints, likely leveraging the Amazon S3 brand to deceive targets. No specific drainer kit signatures were confirmed, but the domain follows patterns consistent with credential phishing campaigns targeting cloud service users. Technical indicators confirm the domain's malicious classification. VirusTotal reports 12 out of 95 security vendors flagging the domain as malicious. Registered through MarkMonitor Inc., the domain was created on April 24, 2026, an unusually future-dated registration suggesting possible obfuscation or misconfiguration. It resolves to IP address 16.15.252.194, hosted on AWS EC2 in the us-east-1 region. Google Safe Browsing explicitly flags the domain as phishing, and it appears on one security blocklist. The SSL certificate is issued by Amazon, using the Amazon RSA 2048 M04 template, which aligns with legitimate AWS services but does not mitigate the domain's malicious intent. The domain is currently offline, reducing immediate exposure risk. However, historical activity and infrastructure reuse remain a concern. Response actions likely included takedown requests to the hosting provider and registrar, though no public confirmation exists. Remaining risk includes potential reactivation under a similar domain or IP, as well as the possibility of stolen credentials being exploited in follow-up attacks. Organizations should monitor for connections to 16.15.252.194 and related AWS-hosted endpoints, while users should verify cloud storage URLs for authenticity before entering credentials.
Intelijen Keamanan Jaringan
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| YARAhub by abuse.ch | yamzoza-north-007-amazon.s3.us-east-1.amazonaws.com/moon.html |
malware | Detects file containing Telegram Bot API |
Alur Tanggapan Ancaman Pipeline
Status Daftar Blokir Publik
Tangkapan tersimpan
Intelijen Domain
Rincian teknisDNS, SAN SSL, cap waktu
Analisis VirusTotal
Bukti & Laporan Eksternal
Apakah Anda Terpengaruh oleh Situs Ini?
Jika Anda memasukkan kredensial akun, informasi pribadi atau pembayaran, atau mengunduh file dari domain ini, segera ambil tindakan. Di bawah ini adalah sumber daya untuk membantu Anda melaporkan insiden tersebut dan melindungi diri Anda sendiri.
Laporkan kepada Pihak Berwenang di Daerah Anda
Pilih negara Anda untuk mendapatkan kontak resmi kejahatan dunia maya, atau membuat draf pengaduan →.
Periksa Domain Apa Pun
Analisis ancaman menggunakan daftar blokir yang disimpan, WHOIS, DNS, dan bukti pemindaian publik
Pindai SekarangLaporkan Phishing
Laporkan domain yang mencurigakan ke basis data ancaman kami — lindungi komunitas
LaporanPemberitahuan Ancaman Real-Time
Laporan phishing terbaru dan perubahan ketersediaan yang diamati
PantauTetap Terinformasi, Tetap Aman
Pantau ancaman secara langsung atau ajukan keberatan terhadap daftar ini jika Anda yakin ini merupakan false positive