amazonuvip[.]vip
“amazonuvip.vip”
Сводка доказательств
The domain amazonuvip.vip is identified as a brand impersonation threat specifically targeting Amazon. Analysis confirms the domain was designed to mimic Amazon’s official branding, likely to deceive users into disclosing credentials or financial information. As of the latest verification, the domain has been taken offline, though prior activity indicates it was actively used in phishing operations. Technical indicators reveal multiple red flags. The domain was flagged by 17 of 95 security vendors on VirusTotal, signaling widespread detection as malicious. Registered on October 10, 2025, through Gname.com Pte. Ltd., the domain lacks an SSL certificate, a critical security omission for any legitimate transactional or login portal. Infrastructure analysis shows it resolved to the IP address 47.253.99.169, hosted under AS45102 (Alibaba (US) Technology Co., Ltd.), and appeared on two security blocklists, including PhishDestroy and PhishingDB. The page title, matching the domain name itself, further suggests a lack of effort to appear authentic. Current status confirms amazonuvip.vip is offline, reducing immediate exposure risk. However, the domain’s infrastructure and registration details remain a concern for potential reactivation or reuse. Organizations and users are advised to block the domain and its associated IP at the network level. Security teams should monitor for similar domains registered through the same registrar or resolving to the same IP range. End users who may have interacted with the domain should reset credentials for Amazon and any linked accounts, enable multi-factor authentication, and review financial statements for unauthorized activity.
Data Coverage
Сигналы безопасности
Процесс реагирования на угрозы
Проверка по блок-листам
10 внешних источников под наблюдением · снимок от 10.08.2026
10 внешних источников под наблюдением Совпадений нет
Хронология обнаружения
-
Статус домена
Доступен → Недоступен
-
Cloudflare Radar
Сканирование Cloudflare Radar сохранено · Открыть сканирование
-
Статус домена
Недоступен → Доступен
Сохранённый снимок
Аналитика доменов
Технические деталиDNS, имена TLS и временные метки
ICANN OVERSIGHT
Аккредитация и контекст RAA
Аккредитация и контекст RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Анализ VirusTotal
Повлиял ли на вас этот сайт?
Если вы ввели учетные данные, личную или платежную информацию или загрузили файл с этого домена, примите немедленные меры. Ниже приведены ресурсы, которые помогут вам сообщить об инциденте и защитить себя.
Сообщите об этом в местные органы власти
Выберите свою страну, чтобы получить официальные контакты по киберпреступности или создать проект жалобы →.
Проверить любой домен
Анализ угроз с использованием сохраненного черного списка, WHOIS, DNS и общедоступных доказательств сканирования.
Сканировать сейчасСообщить о фишинге
Добавляйте подозрительные домены в нашу базу данных угроз — защищайте сообщество
СообщитьПоток оперативных данных об угрозах
Недавние сообщения о фишинге и наблюдаемые изменения доступности
ОтслеживатьБудьте в курсе событий, берегите себя
Отслеживайте актуальные угрозы или оспорьте эту запись, если считаете, что это ложное срабатывание