aamazon-tolfre-nummber[.]webflow[.]io
“404 - Page not found”
Сводка доказательств
This domain is flagged as an elevated-risk brand impersonation threat targeting Amazon. Analysis indicates the infrastructure was designed to mimic legitimate Amazon services, likely to deceive users into divulging credentials, financial details, or other sensitive information. The domain exhibits multiple technical indicators consistent with fraudulent activity, including its deceptive naming convention and association with known malicious patterns. Infrastructure analysis reveals the domain resolves to IP address 172.64.151.8, hosted on Cloudflare’s network (AS13335) in the United States. It is registered through NameCheap, Inc., with a creation date of February 24, 2026, suggesting a recently established operation. Security vendors on VirusTotal flagged the domain in 17 out of 95 scans, while PhishDestroy and at least one other security blocklist have already listed it. The SSL certificate, issued by Google Trust Services (WE1), does not mitigate the risk, as fraudulent domains frequently leverage valid certificates to appear legitimate. The domain’s current status is offline, and its last known page title was '404 - Page not found,' which may indicate takedown efforts or evasion tactics. To mitigate risks associated with this brand impersonation threat, users and organizations should immediately block the domain and its associated IP address (172.64.151.8) at the network level. Security teams should monitor for any attempts to access or interact with the domain, particularly in environments where Amazon-related services are used. End-users should be educated on recognizing deceptive domain names, such as those containing misspellings or unusual subdomains, and encouraged to verify URLs before entering credentials or financial information. If any interaction with the domain occurred, affected accounts should be reviewed for unauthorized activity, and credentials should be reset as a precautionary measure. Organizations should also consider implementing domain monitoring to detect similar impersonation attempts targeting their brand or services.
Data Coverage
Сигналы безопасности
Данные сетевой безопасности
Процесс реагирования на угрозы
Проверка по блок-листам
10 внешних источников под наблюдением · снимок от 12.08.2026
10 внешних источников под наблюдением Совпадений нет
Хронология обнаружения
-
Cloudflare Radar
Сканирование Cloudflare Radar сохранено · Открыть сканирование
Аналитика доменов
Технические деталиDNS, имена TLS и временные метки
Анализ VirusTotal
Повлиял ли на вас этот сайт?
Если вы ввели учетные данные, личную или платежную информацию или загрузили файл с этого домена, примите немедленные меры. Ниже приведены ресурсы, которые помогут вам сообщить об инциденте и защитить себя.
Сообщите об этом в местные органы власти
Выберите свою страну, чтобы получить официальные контакты по киберпреступности или создать проект жалобы →.
Проверить любой домен
Анализ угроз с использованием сохраненного черного списка, WHOIS, DNS и общедоступных доказательств сканирования.
Сканировать сейчасСообщить о фишинге
Добавляйте подозрительные домены в нашу базу данных угроз — защищайте сообщество
СообщитьПоток оперативных данных об угрозах
Недавние сообщения о фишинге и наблюдаемые изменения доступности
ОтслеживатьБудьте в курсе событий, берегите себя
Отслеживайте актуальные угрозы или оспорьте эту запись, если считаете, что это ложное срабатывание