Security Scan Report: recovers3support.s3.eu-north-1.amazonaws.com

Submitted: Oct 20, 2025, 11:48:48 AMCompleted: Oct 20, 2025, 11:49:50 AMpubliccompleted
Loading additional data...

Summary

This website contacted 5 IPs in 2 countries across 2 domains to perform 3 HTTP transactions. The main domain is recovers3support.s3.eu-north-1.amazonaws.com and was registered NaN years ago.

Submitted URL: https://recovers3support.s3.eu-north-1.amazonaws.com/recovery.html

AI Security Verdict

High Risk

Confidence: 92%

7
Risk Score

High‑risk phishing page impersonating Ledger on an S3 bucket.

Risk Factors
Brand impersonation on an unusual cloud‑storage domain
Use of a generic S3 subdomain to host a Ledger‑branded page
Unranked domain presenting a major brand
Domain age information unavailable

Details

Page Title

Ledger Recovery — Under Maintenance

Scan Type

public

Language

🇺🇸

English

(51% confidence)

Category

unknown

(0%)

Domain Information

You're looking at domain 'recovers3support.s3.eu-north-1.amazonaws.com' on the commercial generic top-level domain (.com) with subdomain 'recovers3support.s3.eu-north-1'. Count 9 characters in 'amazonaws' with four vowels and five consonants. Splitting it apart reveals three words: amazon, aw, s. Median word length is two characters. Most frequently, 'amazonky' shows up in Czech. Secondary signals appear in Slovak and Croatian.

Screenshot

Security scan screenshot of https://recovers3support.s3.eu-north-1.amazonaws.com/recovery.html

Page Load Overview

16.87s
Total Load Time
3
HTTP Requests
2
Domains
4 KB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:51%
Script:Latin
Direction:ltr

Detection Details

Language Code:en
Detection Confidence:51%
Script Type:Latin
HTML Lang Attribute:en
Text Length:270 chars
Detector Agreement:100%

Website Classification

Primary Category

unknown0% confidence
Type: static
Method: structural

All Detected Categories

No categories detected

Detected Features

No structural features detected

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
3185.15.59.240United States
AS14907WIKIMEDIA
016.12.9.26Stockholm, Stockholm County, Sweden
AS16509AMAZON-02
02a02:ec80:300:ed1a::2:bUnited States
AS14907WIKIMEDIA
03.5.218.224Stockholm, Stockholm County, Sweden
AS16509AMAZON-02
03.5.218.201Stockholm, Stockholm County, Sweden
AS16509AMAZON-02
35--

Detected Technologies2

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T19671933296524035B023E2553BE7A30E3674F217D21BB9387EDD21D58F85ADEC5E3628

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

96:nhRIXbMeBj8j80hiPEq1M7Z0HFYVhhzE+Enpds/X/Vj:hRqJ8j80hiPEqS7ZceVhhzEJaf/Vj

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:3584:gAmQAAEARoQAAAAQBAQAAgEBAQAawAig4CAEBRAAGIEABIJEAAAYVlCAFAAAEQACAAgBAAMgoFATEAEGAIwIBQCAAAAICAQD

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:f0f8ffe7e7ffff7f
Perceptual Hash:e34b484d63668dd9
Difference Hash:0111494c4c088480
Wavelet Hash:00103c2527270f0f
Color Hash:#1f2d93

Other Hashes

Crop Resistant:0111494c4c088480

Scan History

Scan history not available

Unable to load historical scan data