Phishing detection: amazon-ae-relay.apps.prov.cx

Amazon
https://amazon-ae-relay.apps.prov.cx Access site
Screenshot
Screenshot of amazon-ae-relay.apps.prov.cx
Investigate
Domain amazon-ae-relay.apps.prov.cx29 CT hosts on apex
URL https://amazon-ae-relay.apps.prov.cx
Phishunt analysis Beta
38 medium suspicion suspiciousheuristic risk score · not a probability
Why?
  • +6.1 Google Safe Browsing
  • +5.3 Keyword match
  • +4.5 Brand in title
  • +4.1 Brand in screenshot
  • +3.2 Young domain
  • +3.0 OpenPhish
  • +2.6 Brand in subdomain
  • +2.2 Country mismatch
  • +1.1 ASN reputation
  • +1.1 No CSP header
  • +1.1 No HSTS header
  • +0.9 No registrar lock
  • +0.7 Bulletproof DNS
  • +0.6 Long domain
  • +0.6 Login text in screenshot
  • +0.6 Suspicious TLD
  • +0.3 Deep subdomain
  • +0.2 Hyphens
20 signals fired · detector v3.0.0
AI analysis AIBeta
Credential harvesting

Site impersonates Amazon targeting UAE users, hosted on Bulgarian infrastructure under an obscure PaaS subdomain. It displays login-related content and is flagged as social engineering by Google Safe Browsing and OpenPhish.

Google Safe BrowsingOpenPhishBrand in subdomain
AI-generated from stored detector signals - the AI never visited the site. · 2026-07-27 · confidence 82%
Domain & Network
Whois
Network
Country BulgariaBulgaria
Hosting Tamatiya EOOD
ASN AS50360
TLS Cert -
External detection Google Safe Browsing OpenPhish
GSB category: SOCIAL_ENGINEERING
CleanPhishTank · TweetFeed · urlscan.io
Report this phishing

Tracked from 2026-07-27 13:02 UTC  ·  Last refreshed 2026-08-23 21:30 UTC