kartiksinghks2005-arch[.]github[.]io
“Amazon”
kartiksinghks2005-arch.github.io — Contenuto non disponibile. Simulazione del marchio: Amazon; Tipo di truffa: Generic Phishing. Riepilogo delle prove: VirusTotal 8/91 (alphaMountain.ai, Emsisoft, G-Data, Gridinsoft, MalwareURL); PhishDestroy score 74/100. Registrar: GitHub.
L’analisi dettagliata di PhishDestroy AI resta in inglese per preservare il rapporto forense originale.
This domain, kartiksinghks2005-arch.github.io, is flagged as a high-risk phishing resource impersonating Amazon. Analysis indicates the page title explicitly mimics the legitimate Amazon website, suggesting an intent to deceive users into submitting login credentials, payment details, or other sensitive information. No specific drainer kit signatures have been identified, but the generic phishing classification aligns with common credential harvesting tactics. Infrastructure analysis reveals the domain resolves to IP address 185.199.109.153, hosted under AS54113 (Fastly, Inc.) in the United States. The domain is registered through GitHub, Inc., leveraging a Let's Encrypt SSL certificate (R12) to present a false sense of security. VirusTotal reports 8 out of 95 security vendors flagging this domain as malicious, while it appears on one additional security blocklist. The page remains active, with no evidence of takedown or sinkholing at the time of analysis. Current status confirms the domain is still operational, posing an ongoing risk to users. Response actions should include immediate blacklisting in enterprise security tools, DNS filtering, and endpoint protection rules. Organizations are advised to monitor for connections to 185.199.109.153 and alert on any user interactions with the domain. Despite partial vendor detection, the remaining risk is classified as high due to the active status and brand impersonation of a major e-commerce platform. Users should verify domain authenticity before entering credentials and report suspicious activity to security teams.
Pipeline di risposta alle minacce
Stato della lista di blocco pubblica
Tecnologie · 3 identified
Fastly is a cloud computing services provider. Fastly's cloud platform provides a content delivery network, Internet security services, load balancing, and video & streaming services.
www.fastly.com Confidenza al 100%Analisi di VirusTotal
Dati e relazioni esterne
Questo sito ti ha influenzato in qualche modo?
Se hai inserito credenziali dell'account, informazioni personali o di pagamento oppure hai scaricato un file da questo dominio, agisci immediatamente. Di seguito sono riportate le risorse per aiutarti a segnalare l'incidente e proteggerti.
Segnalalo alle autorità locali
Seleziona il tuo Paese per ottenere contatti ufficiali del crimine informatico o creare una bozza di reclamo →.
Verifica qualsiasi dominio
Analisi delle minacce utilizzando blocklist archiviate, WHOIS, DNS e prove di scansione pubblica
Scansiona oraSegnala un tentativo di phishing
Segnala i domini sospetti al nostro database delle minacce — proteggi la comunità
SegnalaFeed in tempo reale sulle minacce
Segnalazioni recenti di phishing e modifiche osservate della disponibilità
MonitoraRimani informato, rimani al sicuro
Controlla le minacce in tempo reale oppure contesta questa segnalazione se ritieni che si tratti di un falso positivo