kartiksinghks2005-arch[.]github[.]io
“Amazon”
kartiksinghks2005-arch.github.io — Контент недоступний. Уособлення бренду: Amazon; Тип шахрайства: Generic Phishing. Зведення доказів: VirusTotal 8/91 (alphaMountain.ai, Emsisoft, G-Data, Gridinsoft, MalwareURL); PhishDestroy score 74/100. Реєстратор: GitHub.
Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.
This domain, kartiksinghks2005-arch.github.io, is flagged as a high-risk phishing resource impersonating Amazon. Analysis indicates the page title explicitly mimics the legitimate Amazon website, suggesting an intent to deceive users into submitting login credentials, payment details, or other sensitive information. No specific drainer kit signatures have been identified, but the generic phishing classification aligns with common credential harvesting tactics. Infrastructure analysis reveals the domain resolves to IP address 185.199.109.153, hosted under AS54113 (Fastly, Inc.) in the United States. The domain is registered through GitHub, Inc., leveraging a Let's Encrypt SSL certificate (R12) to present a false sense of security. VirusTotal reports 8 out of 95 security vendors flagging this domain as malicious, while it appears on one additional security blocklist. The page remains active, with no evidence of takedown or sinkholing at the time of analysis. Current status confirms the domain is still operational, posing an ongoing risk to users. Response actions should include immediate blacklisting in enterprise security tools, DNS filtering, and endpoint protection rules. Organizations are advised to monitor for connections to 185.199.109.153 and alert on any user interactions with the domain. Despite partial vendor detection, the remaining risk is classified as high due to the active status and brand impersonation of a major e-commerce platform. Users should verify domain authenticity before entering credentials and report suspicious activity to security teams.
Процес реагування на загрози Pipeline
Статус у публічних блоклистах
Технології · 3 identified
Fastly is a cloud computing services provider. Fastly's cloud platform provides a content delivery network, Internet security services, load balancing, and video & streaming services.
www.fastly.com 100% впевненостіАналіз VirusTotal
Докази та зовнішні звіти
Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога