vishnutejaswiniravipati[.]github[.]io
“Amazon”
vishnutejaswiniravipati.github.io — 内容不可用. 品牌冒充:Amazon; 诈骗类型:Brand Impersonation. 证据摘要: VirusTotal 5/91 (alphaMountain.ai, Emsisoft, Gridinsoft, Netcraft, Webroot); URLScan malicious verdict; PhishDestroy score 65/100. 注册商: GitHub.
为保留原始取证记录,下方的 PhishDestroy AI 详细分析仍使用英文。
The domain vishnutejaswiniravipati.github.io is currently flagged as an active credential theft operation targeting Amazon users. Analysis indicates the page is designed to harvest login credentials by impersonating the legitimate Amazon platform, a tactic commonly associated with account takeover fraud and unauthorized financial transactions. The domain remains operational as of the latest assessment, posing a direct risk to users who may unknowingly submit sensitive authentication details. Infrastructure analysis reveals the domain is hosted on GitHub Pages, registered through GitHub, Inc., and resolves to the IP address 185.199.109.153, associated with AS54113 (Fastly, Inc.) in the United States. The SSL certificate is issued by Let's Encrypt (R12), a common but not exclusive indicator of legitimate hosting. The domain is flagged by 5 of 95 security vendors on VirusTotal, and appears on at least one security blocklist, specifically PhishDestroy. The page title explicitly displays 'Amazon,' reinforcing the brand impersonation strategy. No historical registration data is available, as the domain leverages GitHub's subdomain infrastructure, which does not provide traditional WHOIS records. Current risk assessment classifies this domain as high-severity due to its active status, brand impersonation of a major e-commerce platform, and direct targeting of user credentials. Users are strongly advised to avoid interacting with the domain and to verify the authenticity of any Amazon-related communications through official channels. Organizations should update web filtering policies to block access to this domain and monitor for indicators of compromise, including unusual login attempts or unauthorized transactions linked to Amazon accounts. Security teams are recommended to review logs for connections to 185.199.109.153 and correlate with other threat intelligence feeds to identify potential exposure.
威胁响应 Pipeline
公共封禁名单状态
所用技术 · 3 identified
Fastly is a cloud computing services provider. Fastly's cloud platform provides a content delivery network, Internet security services, load balancing, and video & streaming services.
www.fastly.com 置信度 100%VirusTotal 分析
证据与外部报告
您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。