Scan report · 2 months agoPublic
Verdict

What happened

Step by step, from what the scanner recorded.
Load 11.4 s · 9 requests
01 · Visitor openstraefik.ww17.jorgazsb.scotiabank-secure.info
02 · Redirected · 1 hopamjbc.com/iuTTtmLvaYJbURWOUvBPBlJXp/1…nnrnoodnrdwboa8e7nbqoadekya
03 · Page shown
amjbc.com
04 · File delivered · malicious8938bfc8-0c3e-4112-a155-332e1cf1146e.html

Dangerous — confirmed threat

Automated

The file it serves was analysed and found malicious. We found strong evidence that this site is malicious — for example a phishing page, a scam, or hostile code. Treat anything it asked for (passwords, card details, codes) as exposed.

What to do

Do not enter any information or download anything. If you already did, change those passwords now and contact your bank if payment details were involved. Block or report the link to your team.

This reflects the evidence found at the time of the scan. If you believe it is a mistake, you can escalate it for analyst review.

Findings

Strongest first
MalwareMalware found in the downloaded file
8938bfc8-0c3e-4112-a155-332e1cf1146e.html

Our Content Inspection engine downloaded the file this URL serves and analyzed it as a real payload — it matched known malware. Do not open or run this file.

Success

SHA-256 271fe31ea362ab8775e8400cf1ab39b632d7a64fc70c4f97d3dec71ed612c772

Infrastructure

IP
172.239.194.103AKAMAI-LINODE-AP - Akamai Connected Cloud, SG · AS63949US
TLS
CN=YE1, O=Let's Encrypt, C=US · expires Oct 6, 2026
Redirects
1 hop · / → /iuTTtmLvaYJbURWOUvBPBlJXp/1…nnrnoodnrdwboa8e7nbqoadekya

WHOIS

Registrar
Dynadot Inc
Created
Dec 12, 2025
Expires
Dec 12, 2026
Nameservers
ns1.oh313.parklogic.comns2.oh313.parklogic.com
11 malicious6 suspicious

Hashes & fingerprints

Page capture

Live

Engines

7 · time to verdict

Page

HTTP
200 · Completed
Load
11.41 s · 9 requests
Stack · 2OpenRestyNginx