Security Scan Report: plustwebnet.s3.dualstack.us-east-1.amazonaws.com

Redirected to: https://www.epicertification.com/inosmdjs993jdjsjjejjejewekwkemejjrejre84ekr/login.php

Submitted: Nov 14, 2025, 6:12:50 PMCompleted: Nov 14, 2025, 6:13:45 PMpubliccompleted
Loading additional data...

Summary

This website contacted 19 IPs in 0 countries across 3 domains to perform 11 HTTP transactions. The main domain is epicertification.com.

Submitted URL: https://plustwebnet.s3.dualstack.us-east-1.amazonaws.com/plus.html

Effective URL: https://www.epicertification.com/inosmdjs993jdjsjjejjejewekwkemejjrejre84ekr/login.phpRedirected

AI Security Verdict

Confirmed Scam

Confidence: 95%

10
Risk Score

Phishing login page hosted on S3, confirmed scam

Risk Factors
Cloud storage domain with password collection form
Brand impersonation of Webmail on suspicious domain
Unranked and likely newly registered domain
Redirect chain to unrelated domain (www.epicertification.com)
Presence of login form on a suspicious domain
Domain age information unavailable

Details

Page Title

Webmail :: Welcome to Webmail

Scan Type

public

Language

🇺🇸

English

(58% confidence)

Category

documentation technical

(66%)

Domain Information

Within the commercial generic top-level domain (.com), 'plustwebnet.s3.dualstack.us-east-1.amazonaws.com' is registered and includes subdomain 'plustwebnet.s3.dualstack.us-east-1'. Count 9 characters in 'amazonaws' with 4 vowels and 5 consonants. Tokenizing the label suggests 3 words: amazon, aw, s. The median word length lands at two characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://plustwebnet.s3.dualstack.us-east-1.amazonaws.com/plus.html

Page Load Overview

34.35s
Total Load Time
11
HTTP Requests
3
Domains
95 KB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:58%
Script:Latin
Direction:ltr

Detection Details

Language Code:en
Detection Confidence:58%
Script Type:Latin
Text Length:337 chars
Detector Agreement:100%

Website Classification

Primary Category

documentation technical66% confidence
Type: webapp
Method: ml+structural

All Detected Categories

documentation technical
66%
technology software
62%
phishing scam
43%
government public service
34%
adult content
29%

Detected Features

Login Form

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
1191.204.208.19UnknownUnknown
052.210.12.80UnknownUnknown
054.231.198.178UnknownUnknown
052.217.119.42UnknownUnknown
02600:1f60:80a0::100f:da1eUnknownUnknown
02600:1f60:8020::100f:c9beUnknownUnknown
02600:1f60:8020::100f:cb23UnknownUnknown
02600:1f60:80a0::100f:db85UnknownUnknown
052.217.224.250UnknownUnknown
052.217.116.90UnknownUnknown
1119--

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T194C1A61061AD1C37A255CA9634D3D6B450EFCD34F64868F9F2BBC8EA55B0C88232177B

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

96:2LVRIVh+F2iYnqK4uVzUuXy8+KY9c51RuWwrD2BoNwBNmF:GiS2dqKxVzUuXy8+KY9c5PuWQSSaBC

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:5679:GEAFQABKIABgEExQCJAEAGACCKxEBiIBIAIAQQACMEKAgIJIFXCSgEEGJAiBgSIABETWAhCwnBSgAwIAlCAAwDQYwBMgGQpC

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:e7e7ffe7efffffff
Perceptual Hash:b3338ccc6666cc99
Difference Hash:084c124c08000000
Wavelet Hash:00001800f0f0f0f0
Color Hash:#d27992

Other Hashes

Crop Resistant:084c124c08000000

Scan History

Scan history not available

Unable to load historical scan data