bnttiz[.]shop
“Amazon Sign-In”
Kanıt özeti
Analysis of bnttiz.shop, created on 19 June 2026 and currently taken offline, identifies a credential‑phishing operation that impersonates Amazon. The site served a page titled “Amazon Sign‑In”, indicating a direct attempt to harvest Amazon user credentials. Infrastructure evidence shows the domain resolves to IP 185.255.198.196, an address allocated to BACK WAVES LIMITED (AS153371) in the United States. The hosting provider is Cloudflare, as indicated by the authoritative nameservers roan.ns.cloudflare.com and zelda.ns.cloudflare.com. The domain uses a Let’s Encrypt /YR2 SSL certificate, which provides HTTPS encryption but does not confer legitimacy. Registration was performed through GNAME.COM PTE.
LTD., a registrar known to host a variety of malicious domains. Risk scoring from Gridinsoft assigns a trust score of 0 / 100, and the domain appears on a single security blocklist. VirusTotal analysis reports that 18 of 91 scanning engines flagged the domain, corroborating its malicious nature. PhishDestroy has also blocked the site, confirming its classification as a credential‑phishing vector. Defenders should immediately add bnttiz.shop and its resolving IP address to network deny lists and DNS filtering policies. Monitoring for any resurgence of the domain or reuse of the same IP block is recommended, as the infrastructure could be repurposed for future campaigns.
Security teams should also audit authentication logs for any Amazon‑related login attempts originating from the identified IP range and enforce multi‑factor authentication for Amazon accounts where possible. Continuous threat‑intel feeds should be consulted for new indicators tied to the registrar GNAME.COM PTE. LTD. or the AS153371 network, as adversaries often recycle these assets. The combination of low trust scores, multiple vendor detections, and confirmed brand impersonation underscores the elevated risk posed by this domain.
Gönderilen kanıt anlık görüntüsü
- Gönderildi
- Kayıt defteri kayıtları
- 1
- Vaka kimliği
PD-20260624-62C626- Yakalanan sayfa başlığı
- Amazon Sign-In
- PDF belgesi
- PDF kanıtı
Hukuki dayanak
Kanıtın tam metni
Illegal Activities: Active phishing operation targeting victims
Fraud & Deception: Impersonation of legitimate services
Identity Theft: Collection of credentials under false pretenses
Applicable Laws (Unknown):
International Anti-Cybercrime Regulations
Budapest Convention on Cybercrime
Universal Fraud Prevention Laws
Phishing activities violate international cybercrime conventions and Unknown's domestic fraud laws.
Action Required: This evidence-backed report demonstrates clear violations requiring suspension per your policies. Continued hosting exposes your organization to regulatory scrutiny and potential legal liability.
Data Coverage
Ağ Güvenliği İstihbaratı
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| Cloudflare DNS | bnttiz.shop |
malicious | Sinkholed |
| OpenDNS | bnttiz.shop |
phishing | Phishing Block |
| DigiCert UltraDNS | bnttiz.shop |
malicious | Sinkholed |
Tehdit Müdahale Pipeline
Engelleme listesi kapsamı
10 izlenen harici kaynak · kayıtlı anlık görüntü 13.08.2026
Kaydedilen görüntü
Etki Alanı Analizi
Teknik ayrıntılarDNS, TLS adları ve zaman damgaları
ICANN OVERSIGHT
Akreditasyon ve RAA bağlamı
Akreditasyon ve RAA bağlamı
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
VirusTotal Analizi
Bu Siteden Etkilendiniz mi?
Hesap kimlik bilgilerini, kişisel bilgileri veya ödeme bilgilerini girdiyseniz ya da bu alan adından bir dosya indirdiyseniz hemen harekete geçin. Aşağıda olayı bildirmenize ve kendinizi korumanıza yardımcı olacak kaynaklar bulunmaktadır.
Yerel Yetkililere Bildirin
resmi siber suç iletişim bilgileri veya şikayet taslağı oluştur → almak için ülkenizi seçin.
Herhangi Bir Alan Adını Kontrol Et
Saklanan engelleme listesi, WHOIS, DNS ve genel tarama kanıtlarını kullanarak tehdit analizi
Şimdi TaraOltalama Olayını Bildir
Şüpheli alan adlarını tehdit veritabanımıza bildirin — topluluğu koruyun
BildirCanlı Tehdit Akışı
Son kimlik avı raporları ve gözlemlenen kullanılabilirlik değişiklikleri
İzleGelişmelerden Haberdar Olun, Güvende Kalın
Canlı tehditleri izleyin veya bunun yanlış bir uyarı olduğunu düşünüyorsanız bu kayda itiraz edin