Security Scan Report: onlinewebportal.s3.eu-north-1.amazonaws.com

Submitted: Oct 22, 2025, 8:35:00 PMCompleted: Oct 22, 2025, 8:37:15 PMpubliccompleted
Loading additional data...

Summary

This website contacted 12 IPs in 4 countries across 10 domains to perform 70 HTTP transactions. The main domain is onlinewebportal.s3.eu-north-1.amazonaws.com.

Submitted URL: https://onlinewebportal.s3.eu-north-1.amazonaws.com/OpenPortal/view.html

AI Security Verdict

High Risk

Confidence: 85%

7
Risk Score

High‑risk phishing page impersonating the IRS on an untrusted S3 domain.

Risk Factors
Brand impersonation on an unusual, unranked domain
Use of a cloud storage URL to host a fake IRS redirect page
Potential credential harvesting via future redirects
Domain age information unavailable

Details

Page Title

IRS Portal - Redirecting...

Scan Type

public

Language

🇺🇸

English

(50% confidence)

Category

government public service

(62%)

Domain Information

You're looking at domain 'onlinewebportal.s3.eu-north-1.amazonaws.com' on the commercial generic top-level domain (.com), featuring subdomain 'onlinewebportal.s3.eu-north-1'. Count 9 characters in 'amazonaws' containing 4 vowels alongside five consonants. Breaking it apart gives three words: amazon, aw, s. Median word length comes out to 2 characters. 'amazonky' most often appears in Czech. You will also see it in Slovak and Croatian contexts.

Screenshot

Security scan screenshot of https://onlinewebportal.s3.eu-north-1.amazonaws.com/OpenPortal/view.html

Page Load Overview

131.23s
Total Load Time
70
HTTP Requests
10
Domains
1.0 MB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:50%
Script:Latin
Direction:ltr

Detection Details

Language Code:en
Detection Confidence:50%
Script Type:Latin
HTML Lang Attribute:en
Text Length:586 chars
Detector Agreement:100%

Website Classification

Primary Category

government public service62% confidence
Type: static
Method: ml+structural

All Detected Categories

government public service
62%

Detected Features

No structural features detected

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
15172.217.18.8United States
AS15169GOOGLE
5172.66.171.172United States
AS13335CLOUDFLARENET
5104.102.60.252Frankfurt am Main, Hesse, Germany
AS16625AKAMAI-AS
599.84.152.87United States
AS16509AMAZON-02
523.39.229.82Philadelphia, Pennsylvania, United States
AS20940Akamai International B.V.
53.5.217.255Stockholm, Stockholm County, Sweden
AS16509AMAZON-02
523.39.229.48Philadelphia, Pennsylvania, United States
AS20940Akamai International B.V.
5104.26.0.125United States
AS13335CLOUDFLARENET
5104.20.20.192United States
AS13335CLOUDFLARENET
5132.148.210.175United States
AS398101GO-DADDY-COM-LLC
7012--

Detected Technologies3

Content Similarity HashesFor malware variant detection

Image Hashes

Perceptual Hashes

Average Hash:N/A
Perceptual Hash:N/A
Difference Hash:N/A
Wavelet Hash:N/A
Color Hash:N/A

Other Hashes

Crop Resistant:N/A

Scan History

Scan history not available

Unable to load historical scan data