Scan report · 9 days agoPublic

iuiut.nwfdk.com

47.245.4.14AS45102 · US
Landed onhttps://www.amazon.co.jp/· 1 redirect

the page presents itself as Amazon and wears the brand's name in a host the brand does not own (amazon.co.jp)

Engine tags
Verdict

What happened

Step by step, from what the scanner recorded.
Load 4.0 s · 416 requests
01 · Visitor opensiuiut.nwfdk.com
02 · Redirected · 1 hopwww.amazon.co.jp
03 · Page shown
Amazon.co.jp | Books, Apparel, Electronics, Groceries & morestyled as Amazon · high
04 · OutcomeCredential phishingA login page wearing a brand it does not own.

Be careful — warning signs found

Automated

It presents itself as Amazon while being hosted somewhere Amazon does not own. This site shows signs commonly seen in scams or impersonation, but we could not confirm it for certain. It may be a real threat, or it may be a legitimate site that simply looks unusual to our automated checks.

What to do

Avoid entering passwords or payment details until you are sure it is genuine. Open the company directly from its known website or app instead of this link. Check the evidence below and escalate to your analyst if unsure.

"Suspicious" is a caution, not a confirmation — it can be a false alarm. The evidence below explains why it was flagged.

Findings

Strongest first
Suspicious fileSuspicious content in the downloaded file
0a3ef7a5-06d2-434b-8eaf-54847534b41d.html

Our Content Inspection engine downloaded the file this URL serves and analyzed it. The payload shows traits commonly seen in malware. Treat it as unsafe until verified.

Success

SHA-256 e92360c39ff751c39db9c2a9a08c2a496fe55af0ae3e7a16c14387c4eeef17c3

SupportingBrand impersonation detected
Amazon · high

The page presents itself as a known brand (brand keywords/branding detected).

Analyst noteHigh confidence: the host wears the brand's name and the brand does not own it.

InfoCross-domain scripts injected at runtime
13 script(s)

The page dynamically injected scripts from other domains. This is extremely common on legitimate sites (CDNs, analytics, asset domains) and is shown for context only.

Analyst noteNoisy by itself — a CDN/asset domain (e.g. a brand's own *.githubassets.com) is normal. Only meaningful if the source domain is unrelated/suspicious.

Infrastructure

IP
47.245.4.14ALIBABA-CN-NET - Alibaba (US) Technology Co., Ltd., CN · AS45102US
TLS
CN=YE1, O=Let's Encrypt, C=US · expires Dec 23, 2026
Redirects
1 hop · / → /

WHOIS

Registrar
Vantage of Convergence (Chengdu) Technology Co., Ltd.
Created
Nov 18, 2025
Expires
Nov 18, 2026
Nameservers
kiki.ns.cloudflare.comnorman.ns.cloudflare.com
37 malicious25 suspicious

Hashes & fingerprints

Page capture

Live

Title “Amazon.co.jp | Books, Apparel, Electronics, Groceries & more” · brand shown: Amazon (high)

Engines

7 · time to verdict

Page

HTTP
200 · Completed
Title
Amazon.co.jp | Books, Apparel, Electronics, Groceries & more
Load
3.98 s · 416 requests
Stack · 5Adobe Audience ManagerAmazon AdvertisingCart FunctionalityjQueryOpen Graph