amznmshs-tlk[.]surge[.]sh
“Login To Your Account”
amznmshs-tlk.surge.sh — Contenuto non disponibile. Simulazione del marchio: Amazon; Tipo di truffa: Credential Phishing. Riepilogo delle prove: VirusTotal 15/91 (ADMINUSLabs, alphaMountain.ai, BitDefender, Ermes, ESET); URLScan malicious verdict; Google Safe Browsing flagged; CF Radar malicious; PhishDestroy score 95/100. Registrar: Surge.sh.
L’analisi dettagliata di PhishDestroy AI resta in inglese per preservare il rapporto forense originale.
The domain amznmshs-tlk.surge.sh is identified as a high-risk credential theft threat. It masquerades as a legitimate login page, potentially targeting users of well-known brands with the intent to harvest sensitive information. This domain is registered through Surge.sh and is actively involved in phishing activities, as evidenced by its deceptive page title 'Login To Your Account'. The threat level is classified as high due to its effective impersonation of trusted entities.
Technical analysis reveals that the domain is flagged by 15 out of 95 security vendors on VirusTotal, indicating significant recognition of its malicious potential. The domain resolves to the IP address 159.203.50.177, located in the United States under AS14061 DigitalOcean, LLC. The SSL certificate is issued by Sectigo Limited, which does not inherently indicate legitimacy due to the ease of obtaining basic SSL certificates. Google Safe Browsing categorizes the domain as phishing, and it also appears on one security blocklist, further confirming its malicious intent.
As of the current status, amznmshs-tlk.surge.sh remains active and poses an ongoing risk to users. Security measures must be enforced to mitigate exposure, including blocking the domain at network perimeters and educating users on the dangers of entering credentials on unfamiliar sites. Organizations should monitor for similar domain patterns and update security protocols to prevent credential theft incidents. The domain is actively flagged by security services and should be treated as a high-priority threat due to the potential for user data compromise.
Informazioni sulla sicurezza di rete
Pipeline di risposta alle minacce
Stato della lista di blocco pubblica
Acquisizione salvata
Analisi dei domini
Dettagli tecniciDNS, SAN SSL, timestamp
Tecnologie · 6 identified
Sovrn is a advertising products and services provider for publishers.
www.sovrn.com Confidenza al 100%Simpli.fi is a programmatic advertising and agency management software.
simpli.fi Confidenza al 100%ShareThis provides free engagement and growth tools (e.g., share buttons, follow buttons, and reaction buttons) for site owners.
sharethis.com Confidenza al 100%jQuery is a JavaScript library which is a free, open-source software designed to simplify HTML DOM tree traversal and manipulation, as well as event handling, CSS animation, and Ajax.
jquery.com Confidenza al 100%33Across is a technology company focused on solving the challenge of consumer attention for automated advertising.
www.33across.com Confidenza al 100%Analisi di VirusTotal
Dati e relazioni esterne
Questo sito ti ha influenzato in qualche modo?
Se hai inserito credenziali dell'account, informazioni personali o di pagamento oppure hai scaricato un file da questo dominio, agisci immediatamente. Di seguito sono riportate le risorse per aiutarti a segnalare l'incidente e proteggerti.
Segnalalo alle autorità locali
Seleziona il tuo Paese per ottenere contatti ufficiali del crimine informatico o creare una bozza di reclamo →.
Verifica qualsiasi dominio
Analisi delle minacce utilizzando blocklist archiviate, WHOIS, DNS e prove di scansione pubblica
Scansiona oraSegnala un tentativo di phishing
Segnala i domini sospetti al nostro database delle minacce — proteggi la comunità
SegnalaFeed in tempo reale sulle minacce
Segnalazioni recenti di phishing e modifiche osservate della disponibilità
MonitoraRimani informato, rimani al sicuro
Controlla le minacce in tempo reale oppure contesta questa segnalazione se ritieni che si tratti di un falso positivo