yamzoza-north-007-amazon[.]s3[.]us-east-1[.]amazonaws[.]com
yamzoza-north-007-amazon.s3.us-east-1.amazonaws.com — Непроверенный. Олицетворение бренда: Amazon; Тип мошенничества: Brand Impersonation. Сводка доказательств: VirusTotal 9/91 (ADMINUSLabs, alphaMountain.ai, BitDefender, Fortinet, G-Data); URLQuery 1 alert; Google Safe Browsing flagged; PhishDestroy score 98/100. Регистратор: MarkMonitor.
Подробный анализ PhishDestroy AI ниже оставлен на английском, чтобы сохранить исходную криминалистическую запись.
This domain, yamzoza-north-007-amazon.s3.us-east-1.amazonaws.com, is identified as a generic phishing threat designed to harvest user credentials. Infrastructure analysis reveals the domain mimics legitimate cloud storage endpoints, likely leveraging the Amazon S3 brand to deceive targets. No specific drainer kit signatures were confirmed, but the domain follows patterns consistent with credential phishing campaigns targeting cloud service users. Technical indicators confirm the domain's malicious classification. VirusTotal reports 12 out of 95 security vendors flagging the domain as malicious. Registered through MarkMonitor Inc., the domain was created on April 24, 2026, an unusually future-dated registration suggesting possible obfuscation or misconfiguration. It resolves to IP address 16.15.252.194, hosted on AWS EC2 in the us-east-1 region. Google Safe Browsing explicitly flags the domain as phishing, and it appears on one security blocklist. The SSL certificate is issued by Amazon, using the Amazon RSA 2048 M04 template, which aligns with legitimate AWS services but does not mitigate the domain's malicious intent. The domain is currently offline, reducing immediate exposure risk. However, historical activity and infrastructure reuse remain a concern. Response actions likely included takedown requests to the hosting provider and registrar, though no public confirmation exists. Remaining risk includes potential reactivation under a similar domain or IP, as well as the possibility of stolen credentials being exploited in follow-up attacks. Organizations should monitor for connections to 16.15.252.194 and related AWS-hosted endpoints, while users should verify cloud storage URLs for authenticity before entering credentials.
Данные сетевой безопасности
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| YARAhub by abuse.ch | yamzoza-north-007-amazon.s3.us-east-1.amazonaws.com/moon.html |
malware | Detects file containing Telegram Bot API |
Процесс реагирования на угрозы
Статус в публичных блок-листах
Сохранённый снимок
Аналитика доменов
Технические сведенияDNS, SAN в протоколе SSL, временные метки
Анализ VirusTotal
Доказательства и внешние отчеты
Повлиял ли на вас этот сайт?
Если вы ввели учетные данные, личную или платежную информацию или загрузили файл с этого домена, примите немедленные меры. Ниже приведены ресурсы, которые помогут вам сообщить об инциденте и защитить себя.
Сообщите об этом в местные органы власти
Выберите свою страну, чтобы получить официальные контакты по киберпреступности или создать проект жалобы →.
Проверить любой домен
Анализ угроз с использованием сохраненного черного списка, WHOIS, DNS и общедоступных доказательств сканирования.
Сканировать сейчасСообщить о фишинге
Добавляйте подозрительные домены в нашу базу данных угроз — защищайте сообщество
СообщитьПоток оперативных данных об угрозах
Недавние сообщения о фишинге и наблюдаемые изменения доступности
ОтслеживатьБудьте в курсе событий, берегите себя
Отслеживайте актуальные угрозы или оспорьте эту запись, если считаете, что это ложное срабатывание