Phishing detection: mcstagingarg.americanexpresspop.com

American Express
https://mcstagingarg.americanexpresspop.com Access site
Screenshot
Screenshot of mcstagingarg.americanexpresspop.com
Investigate
Domain mcstagingarg.americanexpresspop.com5 CT hosts on apex
URL https://mcstagingarg.americanexpresspop.com
Cert Let's Encrypt
Phishunt analysis Beta
31 medium suspicion suspiciousheuristic risk score · not a probability
Why?
  • +5.3 Keyword match
  • +5.1 Site cluster
  • +5.1 urlscan.io
  • +3.7 Brand in domain label
  • +2.2 Country mismatch
  • +1.7 Shared IP cluster
  • +1.4 ASN reputation
  • +1.3 Brand typo
  • +1.1 Cert reuse
  • +1.1 No CSP header
  • +0.9 Young certificate
  • +0.7 Brand in cert SAN
  • +0.7 Unrecognised DNS provider
  • +0.6 Long domain
  • +0.3 Free CA
  • +0.2 Suspicious TLD
  • +0.1 Deep subdomain
19 signals fired · detector v3.0.0
AI analysis AIBeta
Credential harvesting

Site impersonates American Express with the brand name embedded in both the domain and TLS certificate subject. Confirmed malicious by URLScan and hosted on Fastly infrastructure in Germany, it appears designed to harvest card credentials or account login data from American Express customers.

Brand in cert SANurlscan.ioBrand in domain label
AI-generated from stored detector signals - the AI never visited the site. · 2026-09-07 · confidence 82%
Domain & Network
Whois
Network
Country GermanyGermany
Hosting Fastly, Inc.
ASN AS54113
TLS Cert Let's Encrypt
External detection urlscan.io
CleanGoogle Safe Browsing · OpenPhish · PhishTank · TweetFeed
Report this phishing
Network / ASN Fastly, Inc.

Tracked from 2026-09-07 02:10 UTC  ·  Last refreshed 2026-09-10 03:30 UTC