American Express logo

American Express phishing & impersonation

9
Impersonation sightings
9
Distinct hosts
2026-07-11
Last detected
1
Official domains

ScanMalware watches every scanned site for signs it is impersonating American Express — the brand name in the page title or screenshot text, the brand's logo/favicon on a non-official host, and lookalike domains. A match on a host outside American Express's official domains is recorded below.

Official domains
americanexpress.com
Also known as
american express

Detected impersonation sites

HostTitleDetected byVerdictDate
blob:https://pub-2c6a0f984a4543d38cb437400b053dd2.r2.dev/e00c09d1-960c-4c73-990d-9fbe3050c1c9#Log in to My Account | American Express USPage text{"verdict": "Medium Risk", "confidence": 38, "risk level": "medium", "risk factors": ["Suspicious URL Patterns", "Brand Impersonation (American Express)", "Blob URL Detected"], "overall score": 38, "recommendations": ["⚡ Exercise caution when visiting this website", "🛡️ Ensure your browser and antivirus are up to date"], "detailed analysis": {"html forms": {"score": 10, "issues": ["⚠️ CRITICAL: Brand impersonation detected - American Express branding on non-official domain ()"], "password fields": 3, "impersonated brand": "American Express", "brand mismatch detected": true, "impersonated brand slug": "amex", "disguised password fields": 0, "brand impersonation detected": true}, "url analysis": {"score": 0, "issues": ["⚠️ CRITICAL: Blob URL detected as final destination (common phishing technique)"], "positive signals": [], "suspicious patterns": ["Blob URL used to hide phishing content", "Encoded URL/query string embedded in path"]}, "safe browsing": {"score": 100, "issues": [], "threats": [], "positive signals": ["No Google Safe Browsing threats detected"]}, "clone detection": {"score": 100, "issues": [], "warnings": [], "positive signals": ["No visual similarity to known brand sites"]}, "rpki validation": {"total": 8, "total risk": 0, "valid count": 8, "invalid count": 0, "not found count": 0}, "network security": {"score": 65, "issues": [], "mixed content": false, "secure requests": 9, "security headers": {"detected": true}, "insecure requests": 0, "certificate issues": []}, "phishing signals": {"score": 100, "issues": [], "details": {"matched brand": null, "signals detected": [], "is legitimate domain": false}, "warnings": []}, "technology risks": {"score": 50, "issues": [], "security technologies": [], "vulnerable technologies": []}, "redirect analysis": {"score": 0, "issues": ["Blob URL detected in redirect chain", "Blob URL detected in redirect chain"], "total redirects": 3, "blob url detected": true, "protocol downgrades": 0, "same site redirects": 0, "suspicious patterns": 2, "cross domain redirects": 1, "distinct redirect patterns": 1, "compromised wordpress detected": false}}, "threat categories": [], "security indicators": {"negative": ["⚠️ CRITICAL: Blob URL detected as final destination (common phishing technique)", "Blob URL detected in redirect chain", "Blob URL detected in redirect chain", "⚠️ CRITICAL: Brand impersonation detected - American Express branding on non-official domain ()"], "positive": ["Server IPs have valid RPKI ROA coverage", "Good network security practices", "No Google Safe Browsing threats detected", "No visual similarity to known brand sites"], "warnings": []}}2026-07-11View scan →
www.getmyinvoices.comDigitales Rechnungsmanagement | GetMyInvoicesPage text{"verdict": "Low Risk", "confidence": 66, "risk level": "low", "risk factors": ["Mixed Content", "Brand Impersonation (American Express)"], "overall score": 34, "recommendations": ["🔐 Website serves insecure content - data may be intercepted"], "detailed analysis": {"html forms": {"score": 10, "issues": ["⚠️ CRITICAL: Brand impersonation detected - American Express branding on non-official domain (www.getmyinvoices.com)"], "password fields": 0, "impersonated brand": "American Express", "brand mismatch detected": true, "impersonated brand slug": "amex", "disguised password fields": 0, "brand impersonation detected": true}, "url analysis": {"score": 65, "issues": [], "positive signals": ["HTTPS encryption used"], "suspicious patterns": []}, "safe browsing": {"score": 100, "issues": [], "threats": [], "positive signals": ["No Google Safe Browsing threats detected"]}, "clone detection": {"score": 100, "issues": [], "warnings": [], "positive signals": ["No visual similarity to known brand sites"]}, "rpki validation": {"total": 7, "total risk": 0, "valid count": 7, "invalid count": 0, "not found count": 0}, "network security": {"score": 30, "issues": ["Mixed content detected (HTTP resources on HTTPS page)", "1 insecure HTTP requests detected"], "mixed content": true, "secure requests": 609, "security headers": {"detected": true}, "insecure requests": 1, "certificate issues": []}, "phishing signals": {"score": 100, "issues": [], "details": {"matched brand": null, "signals detected": [], "is legitimate domain": false}, "warnings": []}, "technology risks": {"score": 50, "issues": [], "security technologies": [], "vulnerable technologies": []}, "redirect analysis": {"score": 45, "issues": [], "total redirects": 3, "blob url detected": false, "protocol downgrades": 0, "same site redirects": 0, "suspicious patterns": 0, "cross domain redirects": 1, "distinct redirect patterns": 1, "compromised wordpress detected": false}}, "threat categories": [], "security indicators": {"negative": ["Mixed content detected (HTTP resources on HTTPS page)", "1 insecure HTTP requests detected", "⚠️ CRITICAL: Brand impersonation detected - American Express branding on non-official domain (www.getmyinvoices.com)"], "positive": ["Server IPs have valid RPKI ROA coverage", "HTTPS encryption used", "No Google Safe Browsing threats detected", "No visual similarity to known brand sites"], "warnings": []}}2026-07-09View scan →
blob:https://zonastream.planes.click/07742c2c-ebc2-45cc-aef2-1ac630b452df#Log in to My Account | American Express USPage text{"verdict": "Medium Risk", "confidence": 44, "risk level": "medium", "risk factors": ["Suspicious URL Patterns", "Disguised Password Fields", "Brand Impersonation (American Express)", "Blob URL Detected", "References flagged external domain(s): 65.181.116.15"], "overall score": 44, "recommendations": ["⚡ Exercise caution when visiting this website", "🛡️ Ensure your browser and antivirus are up to date"], "detailed analysis": {"html forms": {"score": 0, "issues": ["Disguised password field detected (type=text with password-related name)", "⚠️ CRITICAL: Brand impersonation detected - American Express branding on non-official domain ()"], "password fields": 4, "impersonated brand": "American Express", "brand mismatch detected": true, "impersonated brand slug": "amex", "disguised password fields": 1, "brand impersonation detected": true}, "ioc matches": {"external": [{"indicator": "65.181.116.15", "threat type": "known attacker"}]}, "url analysis": {"score": 0, "issues": ["⚠️ CRITICAL: Blob URL detected as final destination (common phishing technique)"], "positive signals": [], "suspicious patterns": ["Blob URL used to hide phishing content", "Encoded URL/query string embedded in path"]}, "safe browsing": {"score": 100, "issues": [], "threats": [], "positive signals": ["No Google Safe Browsing threats detected"]}, "clone detection": {"score": 100, "issues": [], "warnings": [], "positive signals": ["No visual similarity to known brand sites"]}, "rpki validation": {"total": 13, "total risk": 0, "valid count": 13, "invalid count": 0, "not found count": 0}, "network security": {"score": 65, "issues": [], "mixed content": false, "secure requests": 16, "security headers": {"detected": true}, "insecure requests": 0, "certificate issues": []}, "phishing signals": {"score": 100, "issues": [], "details": {"matched brand": null, "signals detected": [], "is legitimate domain": false}, "warnings": []}, "technology risks": {"score": 50, "issues": [], "security technologies": [], "vulnerable technologies": []}, "redirect analysis": {"score": 0, "issues": ["Blob URL detected in redirect chain", "Blob URL detected in redirect chain"], "total redirects": 3, "blob url detected": true, "protocol downgrades": 0, "same site redirects": 0, "suspicious patterns": 2, "cross domain redirects": 1, "distinct redirect patterns": 1, "compromised wordpress detected": false}}, "threat categories": [], "security indicators": {"negative": ["⚠️ CRITICAL: Blob URL detected as final destination (common phishing technique)", "Blob URL detected in redirect chain", "Blob URL detected in redirect chain", "Disguised password field detected (type=text with password-related name)", "⚠️ CRITICAL: Brand impersonation detected - American Express branding on non-official domain ()"], "positive": ["Server IPs have valid RPKI ROA coverage", "Good network security practices", "No Google Safe Browsing threats detected", "No visual similarity to known brand sites"], "warnings": []}}2026-07-09View scan →
blob:https://zonastream.planes.click/8cabcf84-d37d-49fb-9873-ecc428642b2f#Log in to My Account | American Express USPage text{"verdict": "Medium Risk", "confidence": 44, "risk level": "medium", "risk factors": ["Suspicious URL Patterns", "Disguised Password Fields", "Brand Impersonation (American Express)", "Blob URL Detected", "References flagged external domain(s): 65.181.116.15"], "overall score": 44, "recommendations": ["⚡ Exercise caution when visiting this website", "🛡️ Ensure your browser and antivirus are up to date"], "detailed analysis": {"html forms": {"score": 0, "issues": ["Disguised password field detected (type=text with password-related name)", "⚠️ CRITICAL: Brand impersonation detected - American Express branding on non-official domain ()"], "password fields": 4, "impersonated brand": "American Express", "brand mismatch detected": true, "impersonated brand slug": "amex", "disguised password fields": 1, "brand impersonation detected": true}, "ioc matches": {"external": [{"indicator": "65.181.116.15", "threat type": "known attacker"}]}, "url analysis": {"score": 0, "issues": ["⚠️ CRITICAL: Blob URL detected as final destination (common phishing technique)"], "positive signals": [], "suspicious patterns": ["Blob URL used to hide phishing content", "Encoded URL/query string embedded in path"]}, "safe browsing": {"score": 100, "issues": [], "threats": [], "positive signals": ["No Google Safe Browsing threats detected"]}, "clone detection": {"score": 100, "issues": [], "warnings": [], "positive signals": ["No visual similarity to known brand sites"]}, "rpki validation": {"total": 13, "total risk": 0, "valid count": 13, "invalid count": 0, "not found count": 0}, "network security": {"score": 65, "issues": [], "mixed content": false, "secure requests": 16, "security headers": {"detected": true}, "insecure requests": 0, "certificate issues": []}, "phishing signals": {"score": 100, "issues": [], "details": {"matched brand": null, "signals detected": [], "is legitimate domain": false}, "warnings": []}, "technology risks": {"score": 50, "issues": [], "security technologies": [], "vulnerable technologies": []}, "redirect analysis": {"score": 0, "issues": ["Blob URL detected in redirect chain", "Blob URL detected in redirect chain"], "total redirects": 3, "blob url detected": true, "protocol downgrades": 0, "same site redirects": 0, "suspicious patterns": 2, "cross domain redirects": 1, "distinct redirect patterns": 1, "compromised wordpress detected": false}}, "threat categories": [], "security indicators": {"negative": ["⚠️ CRITICAL: Blob URL detected as final destination (common phishing technique)", "Blob URL detected in redirect chain", "Blob URL detected in redirect chain", "Disguised password field detected (type=text with password-related name)", "⚠️ CRITICAL: Brand impersonation detected - American Express branding on non-official domain ()"], "positive": ["Server IPs have valid RPKI ROA coverage", "Good network security practices", "No Google Safe Browsing threats detected", "No visual similarity to known brand sites"], "warnings": []}}2026-07-09View scan →
blob:https://rtvclub.planes.click/324692bf-4981-4390-b225-90694023d9fd#Log in to My Account | American Express USPage text{"verdict": "Medium Risk", "confidence": 44, "risk level": "medium", "risk factors": ["Suspicious URL Patterns", "Disguised Password Fields", "Brand Impersonation (American Express)", "Blob URL Detected", "References flagged external domain(s): 65.181.116.15"], "overall score": 44, "recommendations": ["⚡ Exercise caution when visiting this website", "🛡️ Ensure your browser and antivirus are up to date"], "detailed analysis": {"html forms": {"score": 0, "issues": ["Disguised password field detected (type=text with password-related name)", "⚠️ CRITICAL: Brand impersonation detected - American Express branding on non-official domain ()"], "password fields": 4, "impersonated brand": "American Express", "brand mismatch detected": true, "impersonated brand slug": "amex", "disguised password fields": 1, "brand impersonation detected": true}, "ioc matches": {"external": [{"indicator": "65.181.116.15", "threat type": "known attacker"}]}, "url analysis": {"score": 0, "issues": ["⚠️ CRITICAL: Blob URL detected as final destination (common phishing technique)"], "positive signals": [], "suspicious patterns": ["Blob URL used to hide phishing content", "Encoded URL/query string embedded in path"]}, "safe browsing": {"score": 100, "issues": [], "threats": [], "positive signals": ["No Google Safe Browsing threats detected"]}, "clone detection": {"score": 100, "issues": [], "warnings": [], "positive signals": ["No visual similarity to known brand sites"]}, "rpki validation": {"total": 11, "total risk": 0, "valid count": 11, "invalid count": 0, "not found count": 0}, "network security": {"score": 65, "issues": [], "mixed content": false, "secure requests": 16, "security headers": {"detected": true}, "insecure requests": 0, "certificate issues": []}, "phishing signals": {"score": 100, "issues": [], "details": {"matched brand": null, "signals detected": [], "is legitimate domain": false}, "warnings": []}, "technology risks": {"score": 50, "issues": [], "security technologies": [], "vulnerable technologies": []}, "redirect analysis": {"score": 0, "issues": ["Blob URL detected in redirect chain", "Blob URL detected in redirect chain"], "total redirects": 3, "blob url detected": true, "protocol downgrades": 0, "same site redirects": 0, "suspicious patterns": 2, "cross domain redirects": 1, "distinct redirect patterns": 1, "compromised wordpress detected": false}}, "threat categories": [], "security indicators": {"negative": ["⚠️ CRITICAL: Blob URL detected as final destination (common phishing technique)", "Blob URL detected in redirect chain", "Blob URL detected in redirect chain", "Disguised password field detected (type=text with password-related name)", "⚠️ CRITICAL: Brand impersonation detected - American Express branding on non-official domain ()"], "positive": ["Server IPs have valid RPKI ROA coverage", "Good network security practices", "No Google Safe Browsing threats detected", "No visual similarity to known brand sites"], "warnings": []}}2026-07-09View scan →
blob:https://zonastream.planes.click/258a2522-e11d-4caf-9841-e4a911f18a76#Log in to My Account | American Express USPage text{"verdict": "Medium Risk", "confidence": 44, "risk level": "medium", "risk factors": ["Suspicious URL Patterns", "Disguised Password Fields", "Brand Impersonation (American Express)", "Blob URL Detected", "References flagged external domain(s): 65.181.116.15"], "overall score": 44, "recommendations": ["⚡ Exercise caution when visiting this website", "🛡️ Ensure your browser and antivirus are up to date"], "detailed analysis": {"html forms": {"score": 0, "issues": ["Disguised password field detected (type=text with password-related name)", "⚠️ CRITICAL: Brand impersonation detected - American Express branding on non-official domain ()"], "password fields": 4, "impersonated brand": "American Express", "brand mismatch detected": true, "impersonated brand slug": "amex", "disguised password fields": 1, "brand impersonation detected": true}, "ioc matches": {"external": [{"indicator": "65.181.116.15", "threat type": "known attacker"}]}, "url analysis": {"score": 0, "issues": ["⚠️ CRITICAL: Blob URL detected as final destination (common phishing technique)"], "positive signals": [], "suspicious patterns": ["Blob URL used to hide phishing content", "Encoded URL/query string embedded in path"]}, "safe browsing": {"score": 100, "issues": [], "threats": [], "positive signals": ["No Google Safe Browsing threats detected"]}, "clone detection": {"score": 100, "issues": [], "warnings": [], "positive signals": ["No visual similarity to known brand sites"]}, "rpki validation": {"total": 12, "total risk": 0, "valid count": 12, "invalid count": 0, "not found count": 0}, "network security": {"score": 65, "issues": [], "mixed content": false, "secure requests": 16, "security headers": {"detected": true}, "insecure requests": 0, "certificate issues": []}, "phishing signals": {"score": 100, "issues": [], "details": {"matched brand": null, "signals detected": [], "is legitimate domain": false}, "warnings": []}, "technology risks": {"score": 50, "issues": [], "security technologies": [], "vulnerable technologies": []}, "redirect analysis": {"score": 0, "issues": ["Blob URL detected in redirect chain", "Blob URL detected in redirect chain"], "total redirects": 3, "blob url detected": true, "protocol downgrades": 0, "same site redirects": 0, "suspicious patterns": 2, "cross domain redirects": 1, "distinct redirect patterns": 1, "compromised wordpress detected": false}}, "threat categories": [], "security indicators": {"negative": ["⚠️ CRITICAL: Blob URL detected as final destination (common phishing technique)", "Blob URL detected in redirect chain", "Blob URL detected in redirect chain", "Disguised password field detected (type=text with password-related name)", "⚠️ CRITICAL: Brand impersonation detected - American Express branding on non-official domain ()"], "positive": ["Server IPs have valid RPKI ROA coverage", "Good network security practices", "No Google Safe Browsing threats detected", "No visual similarity to known brand sites"], "warnings": []}}2026-07-09View scan →
blob:https://pub-09112d252c354ba5a7e853ef4de47615.r2.dev/17d51308-4fea-429d-a90e-81363ff0009e#Log in to My Account | American Express USPage text{"verdict": "Medium Risk", "confidence": 39, "risk level": "medium", "risk factors": ["Suspicious URL Patterns", "Disguised Password Fields", "Brand Impersonation (American Express)", "Blob URL Detected"], "overall score": 39, "recommendations": ["⚡ Exercise caution when visiting this website", "🛡️ Ensure your browser and antivirus are up to date"], "detailed analysis": {"html forms": {"score": 0, "issues": ["Disguised password field detected (type=text with password-related name)", "⚠️ CRITICAL: Brand impersonation detected - American Express branding on non-official domain ()"], "password fields": 4, "impersonated brand": "American Express", "brand mismatch detected": true, "impersonated brand slug": "amex", "disguised password fields": 1, "brand impersonation detected": true}, "url analysis": {"score": 0, "issues": ["⚠️ CRITICAL: Blob URL detected as final destination (common phishing technique)"], "positive signals": [], "suspicious patterns": ["Blob URL used to hide phishing content", "Encoded URL/query string embedded in path"]}, "safe browsing": {"score": 100, "issues": [], "threats": [], "positive signals": ["No Google Safe Browsing threats detected"]}, "clone detection": {"score": 100, "issues": [], "warnings": [], "positive signals": ["No visual similarity to known brand sites"]}, "rpki validation": {"total": 11, "total risk": 0, "valid count": 11, "invalid count": 0, "not found count": 0}, "network security": {"score": 65, "issues": [], "mixed content": false, "secure requests": 14, "security headers": {"detected": true}, "insecure requests": 0, "certificate issues": []}, "phishing signals": {"score": 100, "issues": [], "details": {"matched brand": null, "signals detected": [], "is legitimate domain": false}, "warnings": []}, "technology risks": {"score": 50, "issues": [], "security technologies": [], "vulnerable technologies": []}, "redirect analysis": {"score": 0, "issues": ["Blob URL detected in redirect chain", "Blob URL detected in redirect chain"], "total redirects": 2, "blob url detected": true, "protocol downgrades": 0, "same site redirects": 0, "suspicious patterns": 2, "cross domain redirects": 0, "distinct redirect patterns": 0, "compromised wordpress detected": false}}, "threat categories": [], "security indicators": {"negative": ["⚠️ CRITICAL: Blob URL detected as final destination (common phishing technique)", "Blob URL detected in redirect chain", "Blob URL detected in redirect chain", "Disguised password field detected (type=text with password-related name)", "⚠️ CRITICAL: Brand impersonation detected - American Express branding on non-official domain ()"], "positive": ["Server IPs have valid RPKI ROA coverage", "Good network security practices", "No Google Safe Browsing threats detected", "No visual similarity to known brand sites"], "warnings": []}}2026-07-08View scan →
blob:https://emoslimes.com/3cdc1c0a-223a-4184-b9cb-a07ea4d402ba#Log in to My Account | American Express USPage text{"verdict": "Medium Risk", "confidence": 38, "risk level": "medium", "risk factors": ["Suspicious URL Patterns", "Brand Impersonation (American Express)", "Blob URL Detected"], "overall score": 38, "recommendations": ["⚡ Exercise caution when visiting this website", "🛡️ Ensure your browser and antivirus are up to date"], "detailed analysis": {"html forms": {"score": 10, "issues": ["⚠️ CRITICAL: Brand impersonation detected - American Express branding on non-official domain ()"], "password fields": 3, "impersonated brand": "American Express", "brand mismatch detected": true, "impersonated brand slug": "amex", "disguised password fields": 0, "brand impersonation detected": true}, "url analysis": {"score": 0, "issues": ["⚠️ CRITICAL: Blob URL detected as final destination (common phishing technique)"], "positive signals": [], "suspicious patterns": ["Blob URL used to hide phishing content", "Encoded URL/query string embedded in path"]}, "safe browsing": {"score": 100, "issues": [], "threats": [], "positive signals": ["No Google Safe Browsing threats detected"]}, "clone detection": {"score": 100, "issues": [], "warnings": [], "positive signals": ["No visual similarity to known brand sites"]}, "rpki validation": {"total": 5, "total risk": 2, "valid count": 4, "invalid count": 0, "not found count": 1}, "network security": {"score": 65, "issues": [], "mixed content": false, "secure requests": 6, "security headers": {"detected": true}, "insecure requests": 0, "certificate issues": []}, "phishing signals": {"score": 100, "issues": [], "details": {"matched brand": null, "signals detected": [], "is legitimate domain": false}, "warnings": []}, "technology risks": {"score": 50, "issues": [], "security technologies": [], "vulnerable technologies": []}, "redirect analysis": {"score": 0, "issues": ["Blob URL detected in redirect chain", "Blob URL detected in redirect chain"], "total redirects": 2, "blob url detected": true, "protocol downgrades": 0, "suspicious patterns": 2, "cross domain redirects": 0, "compromised wordpress detected": false}}, "threat categories": [], "security indicators": {"negative": ["⚠️ CRITICAL: Blob URL detected as final destination (common phishing technique)", "Blob URL detected in redirect chain", "Blob URL detected in redirect chain", "⚠️ CRITICAL: Brand impersonation detected - American Express branding on non-official domain ()"], "positive": ["Server IPs have valid RPKI ROA coverage", "Good network security practices", "No Google Safe Browsing threats detected", "No visual similarity to known brand sites"], "warnings": []}}2026-07-08View scan →
blob:https://emoslimes.com/29ac91c9-068f-437f-8a9b-dc7fa99587c8#Log in to My Account | American Express USPage text{"verdict": "Medium Risk", "confidence": 38, "risk level": "medium", "risk factors": ["Suspicious URL Patterns", "Brand Impersonation (American Express)", "Blob URL Detected"], "overall score": 38, "recommendations": ["⚡ Exercise caution when visiting this website", "🛡️ Ensure your browser and antivirus are up to date"], "detailed analysis": {"html forms": {"score": 10, "issues": ["⚠️ CRITICAL: Brand impersonation detected - American Express branding on non-official domain ()"], "password fields": 3, "impersonated brand": "American Express", "brand mismatch detected": true, "impersonated brand slug": "amex", "disguised password fields": 0, "brand impersonation detected": true}, "url analysis": {"score": 0, "issues": ["⚠️ CRITICAL: Blob URL detected as final destination (common phishing technique)"], "positive signals": [], "suspicious patterns": ["Blob URL used to hide phishing content", "Encoded URL/query string embedded in path"]}, "safe browsing": {"score": 100, "issues": [], "threats": [], "positive signals": ["No Google Safe Browsing threats detected"]}, "clone detection": {"score": 100, "issues": [], "warnings": [], "positive signals": ["No visual similarity to known brand sites"]}, "rpki validation": {"total": 6, "total risk": 4, "valid count": 4, "invalid count": 0, "not found count": 2}, "network security": {"score": 65, "issues": [], "mixed content": false, "secure requests": 6, "security headers": {"detected": true}, "insecure requests": 0, "certificate issues": []}, "phishing signals": {"score": 100, "issues": [], "details": {"matched brand": null, "signals detected": [], "is legitimate domain": false}, "warnings": []}, "technology risks": {"score": 50, "issues": [], "security technologies": [], "vulnerable technologies": []}, "redirect analysis": {"score": 0, "issues": ["Blob URL detected in redirect chain", "Blob URL detected in redirect chain"], "total redirects": 2, "blob url detected": true, "protocol downgrades": 0, "suspicious patterns": 2, "cross domain redirects": 0, "compromised wordpress detected": false}}, "threat categories": [], "security indicators": {"negative": ["⚠️ CRITICAL: Blob URL detected as final destination (common phishing technique)", "Blob URL detected in redirect chain", "Blob URL detected in redirect chain", "⚠️ CRITICAL: Brand impersonation detected - American Express branding on non-official domain ()"], "positive": ["Server IPs have valid RPKI ROA coverage", "Good network security practices", "No Google Safe Browsing threats detected", "No visual similarity to known brand sites"], "warnings": []}}2026-07-07View scan →