American Express logo

American Express phishing & impersonation

14
Impersonation sightings
13
Distinct hosts
2026-08-15
Last detected
1
Official domains

ScanMalware watches every scanned site for signs it is impersonating American Express — the brand name in the page title or screenshot text, the brand's logo/favicon on a non-official host, and lookalike domains. A match on a host outside American Express's official domains is recorded below.

Official domains
americanexpress.com
Also known as
american express

Detected impersonation sites

HostTitleDetected byVerdictDate
kjandiaodaadwd1.vercel.appAmerican ExpressPage text{"verdict": "Malicious", "confidence": 95, "risk level": "malicious", "risk factors": ["Brand Impersonation (American Express)", "Google Safe Browsing Threats"], "overall score": 80, "recommendations": ["⚠️ Avoid visiting this website - high security risk detected", "🔒 Use additional security measures if access is necessary", "🚫 Google Safe Browsing detected security threats - avoid interaction", "🛡️ Enable browser security warnings and avoid downloading files"], "detailed analysis": {"html forms": {"score": 10, "issues": ["⚠️ CRITICAL: Brand impersonation detected - American Express branding on non-official domain (kjandiaodaadwd1.vercel.app)"], "password fields": 1, "impersonated brand": "American Express", "brand mismatch detected": true, "impersonated brand slug": "amex", "disguised password fields": 0, "brand impersonation detected": true}, "url analysis": {"score": 65, "issues": [], "positive signals": ["HTTPS encryption used"], "suspicious patterns": []}, "safe browsing": {"score": 0, "issues": ["Google Safe Browsing detected phishing"], "threats": {"SOCIAL ENGINEERING": 1}, "threat summary": ["1 phishing/social engineering threat(s) detected"], "positive signals": []}, "clone detection": {"score": 100, "issues": [], "warnings": [], "positive signals": ["No visual similarity to known brand sites"]}, "rpki validation": {"total": 4, "total risk": 0, "valid count": 4, "invalid count": 0, "not found count": 0}, "network security": {"score": 65, "issues": [], "mixed content": false, "secure requests": 22, "security headers": {"detected": true}, "insecure requests": 0, "certificate issues": []}, "phishing signals": {"score": 100, "issues": [], "details": {"matched brand": null, "signals detected": [], "is legitimate domain": false}, "warnings": []}, "technology risks": {"score": 50, "issues": [], "security technologies": [], "vulnerable technologies": []}, "redirect analysis": {"score": 50, "issues": [], "total redirects": 0, "blob url detected": false, "protocol downgrades": 0, "suspicious patterns": 0, "cross domain redirects": 0, "compromised wordpress detected": false}}, "threat categories": ["Credential Phishing"], "security indicators": {"negative": ["⚠️ CRITICAL: Brand impersonation detected - American Express branding on non-official domain (kjandiaodaadwd1.vercel.app)", "Google Safe Browsing detected phishing"], "positive": ["Server IPs have valid RPKI ROA coverage", "HTTPS encryption used", "Good network security practices", "No visual similarity to known brand sites"], "warnings": []}}2026-08-15View scan →
kjandiaodaadwd1.vercel.appAmerican ExpressPage text{"verdict": "Malicious", "confidence": 95, "risk level": "malicious", "risk factors": ["Brand Impersonation (American Express)", "Google Safe Browsing Threats"], "overall score": 80, "recommendations": ["⚠️ Avoid visiting this website - high security risk detected", "🔒 Use additional security measures if access is necessary", "🚫 Google Safe Browsing detected security threats - avoid interaction", "🛡️ Enable browser security warnings and avoid downloading files"], "detailed analysis": {"html forms": {"score": 10, "issues": ["⚠️ CRITICAL: Brand impersonation detected - American Express branding on non-official domain (kjandiaodaadwd1.vercel.app)"], "password fields": 1, "impersonated brand": "American Express", "brand mismatch detected": true, "impersonated brand slug": "amex", "disguised password fields": 0, "brand impersonation detected": true}, "url analysis": {"score": 65, "issues": [], "positive signals": ["HTTPS encryption used"], "suspicious patterns": []}, "safe browsing": {"score": 0, "issues": ["Google Safe Browsing detected phishing"], "threats": {"SOCIAL ENGINEERING": 1}, "threat summary": ["1 phishing/social engineering threat(s) detected"], "positive signals": []}, "clone detection": {"score": 100, "issues": [], "warnings": [], "positive signals": ["No visual similarity to known brand sites"]}, "rpki validation": {"total": 5, "total risk": 0, "valid count": 5, "invalid count": 0, "not found count": 0}, "network security": {"score": 65, "issues": [], "mixed content": false, "secure requests": 23, "security headers": {"detected": true}, "insecure requests": 0, "certificate issues": []}, "phishing signals": {"score": 100, "issues": [], "details": {"matched brand": null, "signals detected": [], "is legitimate domain": false}, "warnings": []}, "technology risks": {"score": 50, "issues": [], "security technologies": [], "vulnerable technologies": []}, "redirect analysis": {"score": 50, "issues": [], "total redirects": 1, "blob url detected": false, "protocol downgrades": 0, "same site redirects": 0, "suspicious patterns": 0, "cross domain redirects": 0, "distinct redirect patterns": 0, "compromised wordpress detected": false}}, "threat categories": ["Credential Phishing"], "security indicators": {"negative": ["⚠️ CRITICAL: Brand impersonation detected - American Express branding on non-official domain (kjandiaodaadwd1.vercel.app)", "Google Safe Browsing detected phishing"], "positive": ["Server IPs have valid RPKI ROA coverage", "HTTPS encryption used", "Good network security practices", "No visual similarity to known brand sites"], "warnings": []}}2026-08-15View scan →
blob:https://pub-21d07aad6c444724a4f9574677900cde.r2.dev/941184fd-82fb-49f3-8bc7-106efe708cf1#Log in to My Account | American Express USPage text{"verdict": "Medium Risk", "confidence": 38, "risk level": "medium", "risk factors": ["Suspicious URL Patterns", "Brand Impersonation (American Express)", "Blob URL Detected"], "overall score": 38, "recommendations": ["⚡ Exercise caution when visiting this website", "🛡️ Ensure your browser and antivirus are up to date"], "detailed analysis": {"html forms": {"score": 10, "issues": ["⚠️ CRITICAL: Brand impersonation detected - American Express branding on non-official domain ()"], "password fields": 3, "impersonated brand": "American Express", "brand mismatch detected": true, "impersonated brand slug": "amex", "disguised password fields": 0, "brand impersonation detected": true}, "url analysis": {"score": 0, "issues": ["⚠️ CRITICAL: Blob URL detected as final destination (common phishing technique)"], "positive signals": [], "suspicious patterns": ["Blob URL used to hide phishing content", "Encoded URL/query string embedded in path"]}, "safe browsing": {"score": 100, "issues": [], "threats": [], "positive signals": ["No Google Safe Browsing threats detected"]}, "clone detection": {"score": 100, "issues": [], "warnings": [], "positive signals": ["No visual similarity to known brand sites"]}, "rpki validation": {"total": 5, "total risk": 0, "valid count": 5, "invalid count": 0, "not found count": 0}, "network security": {"score": 65, "issues": [], "mixed content": false, "secure requests": 5, "security headers": {"detected": true}, "insecure requests": 0, "certificate issues": []}, "phishing signals": {"score": 100, "issues": [], "details": {"matched brand": null, "signals detected": [], "is legitimate domain": false}, "warnings": []}, "technology risks": {"score": 50, "issues": [], "security technologies": [], "vulnerable technologies": []}, "redirect analysis": {"score": 0, "issues": ["Blob URL detected in redirect chain", "Blob URL detected in redirect chain"], "total redirects": 2, "blob url detected": true, "protocol downgrades": 0, "same site redirects": 0, "suspicious patterns": 2, "cross domain redirects": 0, "distinct redirect patterns": 0, "compromised wordpress detected": false}}, "threat categories": [], "security indicators": {"negative": ["⚠️ CRITICAL: Blob URL detected as final destination (common phishing technique)", "Blob URL detected in redirect chain", "Blob URL detected in redirect chain", "⚠️ CRITICAL: Brand impersonation detected - American Express branding on non-official domain ()"], "positive": ["Server IPs have valid RPKI ROA coverage", "Good network security practices", "No Google Safe Browsing threats detected", "No visual similarity to known brand sites"], "warnings": []}}2026-08-08View scan →
escape.flightsEscape Flights – Cheap flight deals departing NYC, LAX, ORD, MDW, MKE, SEA, PDX, DEN, PHX, ATL, SNA, BUR, ONT, and LGB!Page text{"verdict": "Low Risk", "confidence": 73, "risk level": "low", "risk factors": ["Brand Impersonation (American Express)"], "overall score": 27, "recommendations": [], "detailed analysis": {"html forms": {"score": 10, "issues": ["⚠️ CRITICAL: Brand impersonation detected - American Express branding on non-official domain (escape.flights)"], "password fields": 0, "impersonated brand": "American Express", "brand mismatch detected": true, "impersonated brand slug": "amex", "disguised password fields": 0, "brand impersonation detected": true}, "url analysis": {"score": 65, "issues": [], "positive signals": ["HTTPS encryption used"], "suspicious patterns": []}, "safe browsing": {"score": 100, "issues": [], "threats": [], "positive signals": ["No Google Safe Browsing threats detected"]}, "clone detection": {"score": 100, "issues": [], "warnings": [], "positive signals": ["No visual similarity to known brand sites"]}, "rpki validation": {"total": 23, "total risk": 0, "valid count": 23, "invalid count": 0, "not found count": 0}, "network security": {"score": 65, "issues": [], "mixed content": false, "secure requests": 159, "security headers": {"detected": true}, "insecure requests": 0, "certificate issues": []}, "phishing signals": {"score": 100, "issues": [], "details": {"matched brand": null, "signals detected": [], "is legitimate domain": false}, "warnings": []}, "technology risks": {"score": 50, "issues": [], "security technologies": [], "vulnerable technologies": []}, "redirect analysis": {"score": 50, "issues": [], "total redirects": 0, "blob url detected": false, "protocol downgrades": 0, "suspicious patterns": 0, "cross domain redirects": 0, "compromised wordpress detected": false}}, "threat categories": [], "security indicators": {"negative": ["⚠️ CRITICAL: Brand impersonation detected - American Express branding on non-official domain (escape.flights)"], "positive": ["Server IPs have valid RPKI ROA coverage", "HTTPS encryption used", "Good network security practices", "No Google Safe Browsing threats detected", "No visual similarity to known brand sites"], "warnings": []}}2026-07-30View scan →
www.sierrachart.comSierra ChartPage text{"verdict": "Low Risk", "confidence": 72, "risk level": "low", "risk factors": ["Suspicious URL Patterns", "Brand Impersonation (Amex)"], "overall score": 28, "recommendations": [], "detailed analysis": {"html forms": {"score": 10, "issues": ["⚠️ CRITICAL: Brand impersonation detected - Amex branding on non-official domain (www.sierrachart.com)"], "password fields": 1, "impersonated brand": "Amex", "brand mismatch detected": true, "impersonated brand slug": "amex", "disguised password fields": 0, "brand impersonation detected": true}, "url analysis": {"score": 50, "issues": [], "positive signals": ["HTTPS encryption used"], "suspicious patterns": ["Suspicious domain pattern detected"]}, "safe browsing": {"score": 100, "issues": [], "threats": [], "positive signals": ["No Google Safe Browsing threats detected"]}, "clone detection": {"score": 100, "issues": [], "warnings": [], "positive signals": ["No visual similarity to known brand sites"]}, "network security": {"score": 65, "issues": [], "mixed content": false, "secure requests": 22, "security headers": {"detected": true}, "insecure requests": 0, "certificate issues": []}, "phishing signals": {"score": 100, "issues": [], "details": {"matched brand": null, "signals detected": [], "is legitimate domain": false}, "warnings": []}, "technology risks": {"score": 50, "issues": [], "security technologies": [], "vulnerable technologies": []}, "redirect analysis": {"score": 50, "issues": [], "total redirects": 0, "blob url detected": false, "protocol downgrades": 0, "suspicious patterns": 0, "cross domain redirects": 0, "compromised wordpress detected": false}}, "threat categories": [], "security indicators": {"negative": ["⚠️ CRITICAL: Brand impersonation detected - Amex branding on non-official domain (www.sierrachart.com)"], "positive": ["HTTPS encryption used", "Good network security practices", "No Google Safe Browsing threats detected", "No visual similarity to known brand sites"], "warnings": []}}2026-07-25View scan →
blob:https://pub-2c6a0f984a4543d38cb437400b053dd2.r2.dev/e00c09d1-960c-4c73-990d-9fbe3050c1c9#Log in to My Account | American Express USPage text{"verdict": "Medium Risk", "confidence": 38, "risk level": "medium", "risk factors": ["Suspicious URL Patterns", "Brand Impersonation (American Express)", "Blob URL Detected"], "overall score": 38, "recommendations": ["⚡ Exercise caution when visiting this website", "🛡️ Ensure your browser and antivirus are up to date"], "detailed analysis": {"html forms": {"score": 10, "issues": ["⚠️ CRITICAL: Brand impersonation detected - American Express branding on non-official domain ()"], "password fields": 3, "impersonated brand": "American Express", "brand mismatch detected": true, "impersonated brand slug": "amex", "disguised password fields": 0, "brand impersonation detected": true}, "url analysis": {"score": 0, "issues": ["⚠️ CRITICAL: Blob URL detected as final destination (common phishing technique)"], "positive signals": [], "suspicious patterns": ["Blob URL used to hide phishing content", "Encoded URL/query string embedded in path"]}, "safe browsing": {"score": 100, "issues": [], "threats": [], "positive signals": ["No Google Safe Browsing threats detected"]}, "clone detection": {"score": 100, "issues": [], "warnings": [], "positive signals": ["No visual similarity to known brand sites"]}, "rpki validation": {"total": 8, "total risk": 0, "valid count": 8, "invalid count": 0, "not found count": 0}, "network security": {"score": 65, "issues": [], "mixed content": false, "secure requests": 9, "security headers": {"detected": true}, "insecure requests": 0, "certificate issues": []}, "phishing signals": {"score": 100, "issues": [], "details": {"matched brand": null, "signals detected": [], "is legitimate domain": false}, "warnings": []}, "technology risks": {"score": 50, "issues": [], "security technologies": [], "vulnerable technologies": []}, "redirect analysis": {"score": 0, "issues": ["Blob URL detected in redirect chain", "Blob URL detected in redirect chain"], "total redirects": 3, "blob url detected": true, "protocol downgrades": 0, "same site redirects": 0, "suspicious patterns": 2, "cross domain redirects": 1, "distinct redirect patterns": 1, "compromised wordpress detected": false}}, "threat categories": [], "security indicators": {"negative": ["⚠️ CRITICAL: Blob URL detected as final destination (common phishing technique)", "Blob URL detected in redirect chain", "Blob URL detected in redirect chain", "⚠️ CRITICAL: Brand impersonation detected - American Express branding on non-official domain ()"], "positive": ["Server IPs have valid RPKI ROA coverage", "Good network security practices", "No Google Safe Browsing threats detected", "No visual similarity to known brand sites"], "warnings": []}}2026-07-11View scan →
www.getmyinvoices.comDigitales Rechnungsmanagement | GetMyInvoicesPage text{"verdict": "Low Risk", "confidence": 66, "risk level": "low", "risk factors": ["Mixed Content", "Brand Impersonation (American Express)"], "overall score": 34, "recommendations": ["🔐 Website serves insecure content - data may be intercepted"], "detailed analysis": {"html forms": {"score": 10, "issues": ["⚠️ CRITICAL: Brand impersonation detected - American Express branding on non-official domain (www.getmyinvoices.com)"], "password fields": 0, "impersonated brand": "American Express", "brand mismatch detected": true, "impersonated brand slug": "amex", "disguised password fields": 0, "brand impersonation detected": true}, "url analysis": {"score": 65, "issues": [], "positive signals": ["HTTPS encryption used"], "suspicious patterns": []}, "safe browsing": {"score": 100, "issues": [], "threats": [], "positive signals": ["No Google Safe Browsing threats detected"]}, "clone detection": {"score": 100, "issues": [], "warnings": [], "positive signals": ["No visual similarity to known brand sites"]}, "rpki validation": {"total": 7, "total risk": 0, "valid count": 7, "invalid count": 0, "not found count": 0}, "network security": {"score": 30, "issues": ["Mixed content detected (HTTP resources on HTTPS page)", "1 insecure HTTP requests detected"], "mixed content": true, "secure requests": 609, "security headers": {"detected": true}, "insecure requests": 1, "certificate issues": []}, "phishing signals": {"score": 100, "issues": [], "details": {"matched brand": null, "signals detected": [], "is legitimate domain": false}, "warnings": []}, "technology risks": {"score": 50, "issues": [], "security technologies": [], "vulnerable technologies": []}, "redirect analysis": {"score": 45, "issues": [], "total redirects": 3, "blob url detected": false, "protocol downgrades": 0, "same site redirects": 0, "suspicious patterns": 0, "cross domain redirects": 1, "distinct redirect patterns": 1, "compromised wordpress detected": false}}, "threat categories": [], "security indicators": {"negative": ["Mixed content detected (HTTP resources on HTTPS page)", "1 insecure HTTP requests detected", "⚠️ CRITICAL: Brand impersonation detected - American Express branding on non-official domain (www.getmyinvoices.com)"], "positive": ["Server IPs have valid RPKI ROA coverage", "HTTPS encryption used", "No Google Safe Browsing threats detected", "No visual similarity to known brand sites"], "warnings": []}}2026-07-09View scan →
blob:https://zonastream.planes.click/07742c2c-ebc2-45cc-aef2-1ac630b452df#Log in to My Account | American Express USPage text{"verdict": "Medium Risk", "confidence": 44, "risk level": "medium", "risk factors": ["Suspicious URL Patterns", "Disguised Password Fields", "Brand Impersonation (American Express)", "Blob URL Detected", "References flagged external domain(s): 65.181.116.15"], "overall score": 44, "recommendations": ["⚡ Exercise caution when visiting this website", "🛡️ Ensure your browser and antivirus are up to date"], "detailed analysis": {"html forms": {"score": 0, "issues": ["Disguised password field detected (type=text with password-related name)", "⚠️ CRITICAL: Brand impersonation detected - American Express branding on non-official domain ()"], "password fields": 4, "impersonated brand": "American Express", "brand mismatch detected": true, "impersonated brand slug": "amex", "disguised password fields": 1, "brand impersonation detected": true}, "ioc matches": {"external": [{"indicator": "65.181.116.15", "threat type": "known attacker"}]}, "url analysis": {"score": 0, "issues": ["⚠️ CRITICAL: Blob URL detected as final destination (common phishing technique)"], "positive signals": [], "suspicious patterns": ["Blob URL used to hide phishing content", "Encoded URL/query string embedded in path"]}, "safe browsing": {"score": 100, "issues": [], "threats": [], "positive signals": ["No Google Safe Browsing threats detected"]}, "clone detection": {"score": 100, "issues": [], "warnings": [], "positive signals": ["No visual similarity to known brand sites"]}, "rpki validation": {"total": 13, "total risk": 0, "valid count": 13, "invalid count": 0, "not found count": 0}, "network security": {"score": 65, "issues": [], "mixed content": false, "secure requests": 16, "security headers": {"detected": true}, "insecure requests": 0, "certificate issues": []}, "phishing signals": {"score": 100, "issues": [], "details": {"matched brand": null, "signals detected": [], "is legitimate domain": false}, "warnings": []}, "technology risks": {"score": 50, "issues": [], "security technologies": [], "vulnerable technologies": []}, "redirect analysis": {"score": 0, "issues": ["Blob URL detected in redirect chain", "Blob URL detected in redirect chain"], "total redirects": 3, "blob url detected": true, "protocol downgrades": 0, "same site redirects": 0, "suspicious patterns": 2, "cross domain redirects": 1, "distinct redirect patterns": 1, "compromised wordpress detected": false}}, "threat categories": [], "security indicators": {"negative": ["⚠️ CRITICAL: Blob URL detected as final destination (common phishing technique)", "Blob URL detected in redirect chain", "Blob URL detected in redirect chain", "Disguised password field detected (type=text with password-related name)", "⚠️ CRITICAL: Brand impersonation detected - American Express branding on non-official domain ()"], "positive": ["Server IPs have valid RPKI ROA coverage", "Good network security practices", "No Google Safe Browsing threats detected", "No visual similarity to known brand sites"], "warnings": []}}2026-07-09View scan →
blob:https://zonastream.planes.click/8cabcf84-d37d-49fb-9873-ecc428642b2f#Log in to My Account | American Express USPage text{"verdict": "Medium Risk", "confidence": 44, "risk level": "medium", "risk factors": ["Suspicious URL Patterns", "Disguised Password Fields", "Brand Impersonation (American Express)", "Blob URL Detected", "References flagged external domain(s): 65.181.116.15"], "overall score": 44, "recommendations": ["⚡ Exercise caution when visiting this website", "🛡️ Ensure your browser and antivirus are up to date"], "detailed analysis": {"html forms": {"score": 0, "issues": ["Disguised password field detected (type=text with password-related name)", "⚠️ CRITICAL: Brand impersonation detected - American Express branding on non-official domain ()"], "password fields": 4, "impersonated brand": "American Express", "brand mismatch detected": true, "impersonated brand slug": "amex", "disguised password fields": 1, "brand impersonation detected": true}, "ioc matches": {"external": [{"indicator": "65.181.116.15", "threat type": "known attacker"}]}, "url analysis": {"score": 0, "issues": ["⚠️ CRITICAL: Blob URL detected as final destination (common phishing technique)"], "positive signals": [], "suspicious patterns": ["Blob URL used to hide phishing content", "Encoded URL/query string embedded in path"]}, "safe browsing": {"score": 100, "issues": [], "threats": [], "positive signals": ["No Google Safe Browsing threats detected"]}, "clone detection": {"score": 100, "issues": [], "warnings": [], "positive signals": ["No visual similarity to known brand sites"]}, "rpki validation": {"total": 13, "total risk": 0, "valid count": 13, "invalid count": 0, "not found count": 0}, "network security": {"score": 65, "issues": [], "mixed content": false, "secure requests": 16, "security headers": {"detected": true}, "insecure requests": 0, "certificate issues": []}, "phishing signals": {"score": 100, "issues": [], "details": {"matched brand": null, "signals detected": [], "is legitimate domain": false}, "warnings": []}, "technology risks": {"score": 50, "issues": [], "security technologies": [], "vulnerable technologies": []}, "redirect analysis": {"score": 0, "issues": ["Blob URL detected in redirect chain", "Blob URL detected in redirect chain"], "total redirects": 3, "blob url detected": true, "protocol downgrades": 0, "same site redirects": 0, "suspicious patterns": 2, "cross domain redirects": 1, "distinct redirect patterns": 1, "compromised wordpress detected": false}}, "threat categories": [], "security indicators": {"negative": ["⚠️ CRITICAL: Blob URL detected as final destination (common phishing technique)", "Blob URL detected in redirect chain", "Blob URL detected in redirect chain", "Disguised password field detected (type=text with password-related name)", "⚠️ CRITICAL: Brand impersonation detected - American Express branding on non-official domain ()"], "positive": ["Server IPs have valid RPKI ROA coverage", "Good network security practices", "No Google Safe Browsing threats detected", "No visual similarity to known brand sites"], "warnings": []}}2026-07-09View scan →
blob:https://rtvclub.planes.click/324692bf-4981-4390-b225-90694023d9fd#Log in to My Account | American Express USPage text{"verdict": "Medium Risk", "confidence": 44, "risk level": "medium", "risk factors": ["Suspicious URL Patterns", "Disguised Password Fields", "Brand Impersonation (American Express)", "Blob URL Detected", "References flagged external domain(s): 65.181.116.15"], "overall score": 44, "recommendations": ["⚡ Exercise caution when visiting this website", "🛡️ Ensure your browser and antivirus are up to date"], "detailed analysis": {"html forms": {"score": 0, "issues": ["Disguised password field detected (type=text with password-related name)", "⚠️ CRITICAL: Brand impersonation detected - American Express branding on non-official domain ()"], "password fields": 4, "impersonated brand": "American Express", "brand mismatch detected": true, "impersonated brand slug": "amex", "disguised password fields": 1, "brand impersonation detected": true}, "ioc matches": {"external": [{"indicator": "65.181.116.15", "threat type": "known attacker"}]}, "url analysis": {"score": 0, "issues": ["⚠️ CRITICAL: Blob URL detected as final destination (common phishing technique)"], "positive signals": [], "suspicious patterns": ["Blob URL used to hide phishing content", "Encoded URL/query string embedded in path"]}, "safe browsing": {"score": 100, "issues": [], "threats": [], "positive signals": ["No Google Safe Browsing threats detected"]}, "clone detection": {"score": 100, "issues": [], "warnings": [], "positive signals": ["No visual similarity to known brand sites"]}, "rpki validation": {"total": 11, "total risk": 0, "valid count": 11, "invalid count": 0, "not found count": 0}, "network security": {"score": 65, "issues": [], "mixed content": false, "secure requests": 16, "security headers": {"detected": true}, "insecure requests": 0, "certificate issues": []}, "phishing signals": {"score": 100, "issues": [], "details": {"matched brand": null, "signals detected": [], "is legitimate domain": false}, "warnings": []}, "technology risks": {"score": 50, "issues": [], "security technologies": [], "vulnerable technologies": []}, "redirect analysis": {"score": 0, "issues": ["Blob URL detected in redirect chain", "Blob URL detected in redirect chain"], "total redirects": 3, "blob url detected": true, "protocol downgrades": 0, "same site redirects": 0, "suspicious patterns": 2, "cross domain redirects": 1, "distinct redirect patterns": 1, "compromised wordpress detected": false}}, "threat categories": [], "security indicators": {"negative": ["⚠️ CRITICAL: Blob URL detected as final destination (common phishing technique)", "Blob URL detected in redirect chain", "Blob URL detected in redirect chain", "Disguised password field detected (type=text with password-related name)", "⚠️ CRITICAL: Brand impersonation detected - American Express branding on non-official domain ()"], "positive": ["Server IPs have valid RPKI ROA coverage", "Good network security practices", "No Google Safe Browsing threats detected", "No visual similarity to known brand sites"], "warnings": []}}2026-07-09View scan →
blob:https://zonastream.planes.click/258a2522-e11d-4caf-9841-e4a911f18a76#Log in to My Account | American Express USPage text{"verdict": "Medium Risk", "confidence": 44, "risk level": "medium", "risk factors": ["Suspicious URL Patterns", "Disguised Password Fields", "Brand Impersonation (American Express)", "Blob URL Detected", "References flagged external domain(s): 65.181.116.15"], "overall score": 44, "recommendations": ["⚡ Exercise caution when visiting this website", "🛡️ Ensure your browser and antivirus are up to date"], "detailed analysis": {"html forms": {"score": 0, "issues": ["Disguised password field detected (type=text with password-related name)", "⚠️ CRITICAL: Brand impersonation detected - American Express branding on non-official domain ()"], "password fields": 4, "impersonated brand": "American Express", "brand mismatch detected": true, "impersonated brand slug": "amex", "disguised password fields": 1, "brand impersonation detected": true}, "ioc matches": {"external": [{"indicator": "65.181.116.15", "threat type": "known attacker"}]}, "url analysis": {"score": 0, "issues": ["⚠️ CRITICAL: Blob URL detected as final destination (common phishing technique)"], "positive signals": [], "suspicious patterns": ["Blob URL used to hide phishing content", "Encoded URL/query string embedded in path"]}, "safe browsing": {"score": 100, "issues": [], "threats": [], "positive signals": ["No Google Safe Browsing threats detected"]}, "clone detection": {"score": 100, "issues": [], "warnings": [], "positive signals": ["No visual similarity to known brand sites"]}, "rpki validation": {"total": 12, "total risk": 0, "valid count": 12, "invalid count": 0, "not found count": 0}, "network security": {"score": 65, "issues": [], "mixed content": false, "secure requests": 16, "security headers": {"detected": true}, "insecure requests": 0, "certificate issues": []}, "phishing signals": {"score": 100, "issues": [], "details": {"matched brand": null, "signals detected": [], "is legitimate domain": false}, "warnings": []}, "technology risks": {"score": 50, "issues": [], "security technologies": [], "vulnerable technologies": []}, "redirect analysis": {"score": 0, "issues": ["Blob URL detected in redirect chain", "Blob URL detected in redirect chain"], "total redirects": 3, "blob url detected": true, "protocol downgrades": 0, "same site redirects": 0, "suspicious patterns": 2, "cross domain redirects": 1, "distinct redirect patterns": 1, "compromised wordpress detected": false}}, "threat categories": [], "security indicators": {"negative": ["⚠️ CRITICAL: Blob URL detected as final destination (common phishing technique)", "Blob URL detected in redirect chain", "Blob URL detected in redirect chain", "Disguised password field detected (type=text with password-related name)", "⚠️ CRITICAL: Brand impersonation detected - American Express branding on non-official domain ()"], "positive": ["Server IPs have valid RPKI ROA coverage", "Good network security practices", "No Google Safe Browsing threats detected", "No visual similarity to known brand sites"], "warnings": []}}2026-07-09View scan →
blob:https://pub-09112d252c354ba5a7e853ef4de47615.r2.dev/17d51308-4fea-429d-a90e-81363ff0009e#Log in to My Account | American Express USPage text{"verdict": "Medium Risk", "confidence": 39, "risk level": "medium", "risk factors": ["Suspicious URL Patterns", "Disguised Password Fields", "Brand Impersonation (American Express)", "Blob URL Detected"], "overall score": 39, "recommendations": ["⚡ Exercise caution when visiting this website", "🛡️ Ensure your browser and antivirus are up to date"], "detailed analysis": {"html forms": {"score": 0, "issues": ["Disguised password field detected (type=text with password-related name)", "⚠️ CRITICAL: Brand impersonation detected - American Express branding on non-official domain ()"], "password fields": 4, "impersonated brand": "American Express", "brand mismatch detected": true, "impersonated brand slug": "amex", "disguised password fields": 1, "brand impersonation detected": true}, "url analysis": {"score": 0, "issues": ["⚠️ CRITICAL: Blob URL detected as final destination (common phishing technique)"], "positive signals": [], "suspicious patterns": ["Blob URL used to hide phishing content", "Encoded URL/query string embedded in path"]}, "safe browsing": {"score": 100, "issues": [], "threats": [], "positive signals": ["No Google Safe Browsing threats detected"]}, "clone detection": {"score": 100, "issues": [], "warnings": [], "positive signals": ["No visual similarity to known brand sites"]}, "rpki validation": {"total": 11, "total risk": 0, "valid count": 11, "invalid count": 0, "not found count": 0}, "network security": {"score": 65, "issues": [], "mixed content": false, "secure requests": 14, "security headers": {"detected": true}, "insecure requests": 0, "certificate issues": []}, "phishing signals": {"score": 100, "issues": [], "details": {"matched brand": null, "signals detected": [], "is legitimate domain": false}, "warnings": []}, "technology risks": {"score": 50, "issues": [], "security technologies": [], "vulnerable technologies": []}, "redirect analysis": {"score": 0, "issues": ["Blob URL detected in redirect chain", "Blob URL detected in redirect chain"], "total redirects": 2, "blob url detected": true, "protocol downgrades": 0, "same site redirects": 0, "suspicious patterns": 2, "cross domain redirects": 0, "distinct redirect patterns": 0, "compromised wordpress detected": false}}, "threat categories": [], "security indicators": {"negative": ["⚠️ CRITICAL: Blob URL detected as final destination (common phishing technique)", "Blob URL detected in redirect chain", "Blob URL detected in redirect chain", "Disguised password field detected (type=text with password-related name)", "⚠️ CRITICAL: Brand impersonation detected - American Express branding on non-official domain ()"], "positive": ["Server IPs have valid RPKI ROA coverage", "Good network security practices", "No Google Safe Browsing threats detected", "No visual similarity to known brand sites"], "warnings": []}}2026-07-08View scan →
blob:https://emoslimes.com/3cdc1c0a-223a-4184-b9cb-a07ea4d402ba#Log in to My Account | American Express USPage text{"verdict": "Medium Risk", "confidence": 38, "risk level": "medium", "risk factors": ["Suspicious URL Patterns", "Brand Impersonation (American Express)", "Blob URL Detected"], "overall score": 38, "recommendations": ["⚡ Exercise caution when visiting this website", "🛡️ Ensure your browser and antivirus are up to date"], "detailed analysis": {"html forms": {"score": 10, "issues": ["⚠️ CRITICAL: Brand impersonation detected - American Express branding on non-official domain ()"], "password fields": 3, "impersonated brand": "American Express", "brand mismatch detected": true, "impersonated brand slug": "amex", "disguised password fields": 0, "brand impersonation detected": true}, "url analysis": {"score": 0, "issues": ["⚠️ CRITICAL: Blob URL detected as final destination (common phishing technique)"], "positive signals": [], "suspicious patterns": ["Blob URL used to hide phishing content", "Encoded URL/query string embedded in path"]}, "safe browsing": {"score": 100, "issues": [], "threats": [], "positive signals": ["No Google Safe Browsing threats detected"]}, "clone detection": {"score": 100, "issues": [], "warnings": [], "positive signals": ["No visual similarity to known brand sites"]}, "rpki validation": {"total": 5, "total risk": 2, "valid count": 4, "invalid count": 0, "not found count": 1}, "network security": {"score": 65, "issues": [], "mixed content": false, "secure requests": 6, "security headers": {"detected": true}, "insecure requests": 0, "certificate issues": []}, "phishing signals": {"score": 100, "issues": [], "details": {"matched brand": null, "signals detected": [], "is legitimate domain": false}, "warnings": []}, "technology risks": {"score": 50, "issues": [], "security technologies": [], "vulnerable technologies": []}, "redirect analysis": {"score": 0, "issues": ["Blob URL detected in redirect chain", "Blob URL detected in redirect chain"], "total redirects": 2, "blob url detected": true, "protocol downgrades": 0, "suspicious patterns": 2, "cross domain redirects": 0, "compromised wordpress detected": false}}, "threat categories": [], "security indicators": {"negative": ["⚠️ CRITICAL: Blob URL detected as final destination (common phishing technique)", "Blob URL detected in redirect chain", "Blob URL detected in redirect chain", "⚠️ CRITICAL: Brand impersonation detected - American Express branding on non-official domain ()"], "positive": ["Server IPs have valid RPKI ROA coverage", "Good network security practices", "No Google Safe Browsing threats detected", "No visual similarity to known brand sites"], "warnings": []}}2026-07-08View scan →
blob:https://emoslimes.com/29ac91c9-068f-437f-8a9b-dc7fa99587c8#Log in to My Account | American Express USPage text{"verdict": "Medium Risk", "confidence": 38, "risk level": "medium", "risk factors": ["Suspicious URL Patterns", "Brand Impersonation (American Express)", "Blob URL Detected"], "overall score": 38, "recommendations": ["⚡ Exercise caution when visiting this website", "🛡️ Ensure your browser and antivirus are up to date"], "detailed analysis": {"html forms": {"score": 10, "issues": ["⚠️ CRITICAL: Brand impersonation detected - American Express branding on non-official domain ()"], "password fields": 3, "impersonated brand": "American Express", "brand mismatch detected": true, "impersonated brand slug": "amex", "disguised password fields": 0, "brand impersonation detected": true}, "url analysis": {"score": 0, "issues": ["⚠️ CRITICAL: Blob URL detected as final destination (common phishing technique)"], "positive signals": [], "suspicious patterns": ["Blob URL used to hide phishing content", "Encoded URL/query string embedded in path"]}, "safe browsing": {"score": 100, "issues": [], "threats": [], "positive signals": ["No Google Safe Browsing threats detected"]}, "clone detection": {"score": 100, "issues": [], "warnings": [], "positive signals": ["No visual similarity to known brand sites"]}, "rpki validation": {"total": 6, "total risk": 4, "valid count": 4, "invalid count": 0, "not found count": 2}, "network security": {"score": 65, "issues": [], "mixed content": false, "secure requests": 6, "security headers": {"detected": true}, "insecure requests": 0, "certificate issues": []}, "phishing signals": {"score": 100, "issues": [], "details": {"matched brand": null, "signals detected": [], "is legitimate domain": false}, "warnings": []}, "technology risks": {"score": 50, "issues": [], "security technologies": [], "vulnerable technologies": []}, "redirect analysis": {"score": 0, "issues": ["Blob URL detected in redirect chain", "Blob URL detected in redirect chain"], "total redirects": 2, "blob url detected": true, "protocol downgrades": 0, "suspicious patterns": 2, "cross domain redirects": 0, "compromised wordpress detected": false}}, "threat categories": [], "security indicators": {"negative": ["⚠️ CRITICAL: Blob URL detected as final destination (common phishing technique)", "Blob URL detected in redirect chain", "Blob URL detected in redirect chain", "⚠️ CRITICAL: Brand impersonation detected - American Express branding on non-official domain ()"], "positive": ["Server IPs have valid RPKI ROA coverage", "Good network security practices", "No Google Safe Browsing threats detected", "No visual similarity to known brand sites"], "warnings": []}}2026-07-07View scan →