archanayadv969[.]github[.]io
“Amazon”
Observação armazenada
Contraste de títulos observado
Resumo das evidências
This domain is flagged as a high-risk credential theft operation targeting Amazon users. Analysis indicates the site employs brand impersonation techniques to deceive victims into submitting login credentials, payment details, or personal information under false pretenses. The infrastructure mimics legitimate Amazon pages, increasing the likelihood of successful social engineering attacks against unsuspecting users. Infrastructure analysis reveals the domain archanayadv969.github.io resolves to IP address 185.199.111.153, hosted on AS54113 (Fastly, Inc.) in the United States. The site is registered through GitHub, Inc., leveraging its Pages service for hosting. The SSL certificate is issued by Let's Encrypt (R12), providing a superficial layer of legitimacy. VirusTotal detection metrics show 12 out of 95 security vendors flagging the domain as malicious. The domain appears on one security blocklist and remains active at the time of assessment. The page title explicitly displays 'Amazon,' confirming the targeted brand impersonation. Mitigation requires immediate action to prevent credential compromise and financial fraud. Network-level blocking of the domain and its resolving IP (185.199.111.153) is recommended for all endpoints and perimeter security devices. Security teams should prioritize user education on recognizing cloned login pages, particularly those hosted on non-Amazon infrastructure (e.g., github.io subdomains). Multi-factor authentication (MFA) should be enforced for all Amazon accounts to mitigate the impact of stolen credentials. Organizations should monitor for authentication attempts from the identified IP or related GitHub Pages domains, as these may indicate compromised accounts attempting lateral movement or data exfiltration.
Data Coverage
Pipeline de resposta a ameaças
Cobertura de listas de bloqueio
10 fontes externas monitoradas · instantâneo de 11/08/2026
10 fontes externas monitoradas Sem correspondência
Tecnologias
3 tecnologias identificadas com alta confiança
Análise do VirusTotal
Você foi afetado por este site?
Se você inseriu credenciais de conta, informações pessoais ou de pagamento, ou baixou um arquivo deste domínio, tome medidas imediatas. Abaixo estão os recursos para ajudá-lo a relatar o incidente e se proteger.
Notifique as autoridades locais
Selecione seu país para obter contactos oficiais do cibercrime ou crie um rascunho de reclamação →.
Verificar qualquer domínio
Análise de ameaças usando lista de bloqueio armazenada, WHOIS, DNS e evidências de verificação pública
Digitalize agoraDenunciar phishing
Envie domínios suspeitos para nosso banco de dados de ameaças — proteja a comunidade
DenunciarFeed de ameaças em tempo real
Relatórios recentes de phishing e alterações de disponibilidade observadas
MonitorarMantenha-se informado, mantenha-se seguro
Monitore ameaças em tempo real ou conteste esta listagem caso acredite que se trate de um falso positivo