Scan report · 14 days agoPublic
aniv.czklwfl.cn
43.165.128.22AS132203 · SGSubmittedhttps://aniv.czklwfl.cn
Verdict
1 of 7 enginesMaliciousAutomated
- Threat Intelligencemalicious
- Browser Analysisclean
- Network & Hostingclean
- Related Infrastructureclean
- TLS Fingerprintunknown
- Content Inspectionunknown
- Domain Intelligenceunknown
Dangerous — confirmed threat
AutomatedIt is listed on external threat-intelligence feeds. We found strong evidence that this site is malicious — for example a phishing page, a scam, or hostile code. Treat anything it asked for (passwords, card details, codes) as exposed.
What to do
Do not enter any information or download anything. If you already did, change those passwords now and contact your bank if payment details were involved. Block or report the link to your team.
This verdict rests on other evidence: the site never showed us its own page, so its content was not assessed. Re-scan later or verify through a trusted channel.
File
The file was not analysed, so the scan carries no verdict on the file itself.
Infrastructure
- IP
- 43.165.128.22TENCENT-NET-AP-CN - Tencent Building, Kejizhongyi Avenue, CN · AS132203SG
- TLS
- CN=YE2, O=Let's Encrypt, C=US · expires Dec 9, 2026
- Redirects
- 1 hop · / → /api/captcha/page?site_key=amazon&redirect=/
19 malicious11 suspicious
Hashes & fingerprints
Page Hash8fe61efe4aa5460eb3caecbfe8086622b945952855c8beade78f71d8ba7d2b42Favicon Hash1c64f0ff6d2889f7d3dd5ef6c6b5d88e25ac90e486c17e277713f0c6641c5ba4DOM Hashe941186876bb531fea4ac48f6cb3ccecb82168ede90e87d19f289d3810bbc5a8Screenshot pHashe68c993366cc9933JARM1dd40d40d00040d00042d43d000000e1ea2a807a629b496b664cf07ad7c08dJA4Xa373a9f83c6b_7022c563de38_2e3757343cb0Cert Thumbprint886C6C3DC1FF641AA7291F615E247E514BD04BEFCert IssuerCN=YE2, O=Let's Encrypt, C=US
Page capture
LiveTitle “Security Check”
Engines
7 · time to verdictPage
- HTTP
- 200 · Completed
- Title
- Security Check
- Load
- 13.19 s · 9 requests
Stack · 4Cloudflare Bot ManagementhCaptchaNginxCloudflare