Security Scan Report: s3.eu-north-1.amazonaws.com

Redirected to: https://s3.eu-north-1.amazonaws.com/kn-east-1.console.aws.amazon.com001/MonotomicXKj.html?websrc=oBwEER4NLb4zmR8t4LdvpWCQ5qZs075e14O8yH9y4pSkuLN5wgWDz0GVaHuS026MZguhZ5ejKIYMhwPpXM2FiDj7Jo0Q6MJ5DKIbO9cbqtJJFBhrPK1Ve95OVwosoNjfpNF56SugyzQPXpZaeWSErLs7vqFWQ3LBlNyoAv6ySE8KxxPVqPAhkbD3m5uUSFxhqypHkWtlc2836S1zUURaxbOZPO50Ldmm09w1MKZDLucHK8dQYEomUDK60ZkFzHM2EDbjwwdM92NtrZWNp4sIURKyx7mKXXpb8bnMcCE3QcbOyv&dispatch=542&id=164300#[email protected]

Submitted: Nov 21, 2025, 2:04:39 PMCompleted: Nov 21, 2025, 2:07:45 PMpubliccompleted
Loading additional data...

Summary

This website contacted 32 IPs in 3 countries across 7 domains to perform 30 HTTP transactions. The main domain is s3.eu-north-1.amazonaws.com.

Submitted URL: https://s3.eu-north-1.amazonaws.com/kn-east-1.console.aws.amazon.com001/MonotomicXKj.html#[email protected]

Effective URL: https://s3.eu-north-1.amazonaws.com/kn-east-1.console.aws.amazon.com001/MonotomicXKj.html?websrc=oBwEER4NLb4zmR8t4LdvpWCQ5qZs075e14O8yH9y4pSkuLN5wgWDz0GVaHuS026MZguhZ5ejKIYMhwPpXM2FiDj7Jo0Q6MJ5DKIbO9cbqtJJFBhrPK1Ve95OVwosoNjfpNF56SugyzQPXpZaeWSErLs7vqFWQ3LBlNyoAv6ySE8KxxPVqPAhkbD3m5uUSFxhqypHkWtlc2836S1zUURaxbOZPO50Ldmm09w1MKZDLucHK8dQYEomUDK60ZkFzHM2EDbjwwdM92NtrZWNp4sIURKyx7mKXXpb8bnMcCE3QcbOyv&dispatch=542&id=164300#[email protected]Redirected

The Cisco Umbrella rank of the primary domain is #21 of the top 1 million websitesTop 100 Site

AI Security Verdict

Confirmed Scam

Confidence: 95%

9
Risk Score

Phishing page on Amazon S3 collecting credentials – treat as confirmed scam.

Risk Factors
Cloud storage domain presenting a credential‑collection interface
Email address embedded in URL fragment
Brand impersonation ("sekure") on a non‑official domain
Presence of password field without a proper form (suspicious UI)
Absence of any legitimate functionality or content
Domain age information unavailable

Details

Page Title

Sign in sekure account

Scan Type

public

Language

🇺🇸

English

(80% confidence)

Category

unknown

(0%)

Domain Information

You're looking at domain 's3.eu-north-1.amazonaws.com' on the commercial generic top-level domain (.com), featuring subdomain 's3.eu-north-1'. Its registrable label 'amazonaws' stretches across 9 characters holding 4 vowels versus 5 consonants. Segmentation suggests three words: amazon, aw, s. The median word length lands at two characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://s3.eu-north-1.amazonaws.com/kn-east-1.console.aws.amazon.com001/MonotomicXKj.html#creed@sekure.net

Page Load Overview

0.71s
Total Load Time
30
HTTP Requests
7
Domains
256 KB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

Language Code:en
Detection Confidence:80%
Script Type:Latin
HTML Lang Attribute:en
Text Length:307 chars
Detector Agreement:100%

Website Classification

Primary Category

unknown0% confidence
Type: dynamic
Method: structural

All Detected Categories

No categories detected

Detected Features

No structural features detected

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
6104.17.24.14United States
AS13335CLOUDFLARENET
4104.16.174.226United States
AS13335CLOUDFLARENET
413.35.58.10United States
AS16509AMAZON-02
365.8.131.108United States
AS16509AMAZON-02
252.95.171.71Stockholm, Stockholm County, Sweden
AS16509AMAZON-02
2104.18.11.207United States
AS13335CLOUDFLARENET
0104.17.25.14United States
AS13335CLOUDFLARENET
016.12.9.69Stockholm, Stockholm County, Sweden
AS16509AMAZON-02
013.35.58.96United States
AS16509AMAZON-02
0104.18.10.207United States
AS13335CLOUDFLARENET
3032--

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T132D2D65969F744405653F0B83E9FA1053A36800B9C0ECD0C7EAC574CEFA5E75A9B2FA8

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

384:BFQLag2IFuz7Q7RORf+66Jd1RToRY7kPVLdhWHlnCNSyrNe3+Fs3Vdt1ZqL:BFEd2IFqw66Jd1SRYAEnmohDfqL

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:28734:pAJDjkQz9rjDAVZMAAc0IskAAgRAIoQABKxRG03AygNgAEEAhB2KIQkAsGARuxuslANGvqS8IACFxBCJb+xhhAsMkCYtABQS

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:0018383800000000
Perceptual Hash:88cd367633999966
Difference Hash:4db3b3b3310d1101
Wavelet Hash:013d3d3d01010101
Color Hash:#87c58e

Scan History

Scan history not available

Unable to load historical scan data