Phishing detection: mcstagingarg.americanexpresspop.com
American Express Investigate
Domain
mcstagingarg.americanexpresspop.com5 CT hosts on apex
IP
146.75.117.124
URL
https://mcstagingarg.americanexpresspop.com
Cert
Let's Encrypt
Phishunt analysis Beta
31
medium suspicion suspiciousheuristic risk score · not a probability
Why?
- +5.3 Keyword match
- +5.1 Site cluster
- +5.1 urlscan.io
- +3.7 Brand in domain label
- +2.2 Country mismatch
- +1.7 Shared IP cluster
- +1.4 ASN reputation
- +1.3 Brand typo
- +1.1 Cert reuse
- +1.1 No CSP header
- +0.9 Young certificate
- +0.7 Brand in cert SAN
- +0.7 Unrecognised DNS provider
- +0.6 Long domain
- +0.3 Free CA
- +0.2 Suspicious TLD
- +0.1 Deep subdomain
19 signals fired · detector v3.0.0
AI analysis AIBeta
Credential harvesting
Site impersonates American Express with the brand name embedded in both the domain and TLS certificate subject. Confirmed malicious by URLScan and hosted on Fastly infrastructure in Germany, it appears designed to harvest card credentials or account login data from American Express customers.
Brand in cert SANurlscan.ioBrand in domain label
AI-generated from stored detector signals - the AI never visited the site. · 2026-09-07 · confidence 82%
Domain & Network
Whois
Registrar
CSC Corporate Domains, Inc.
Network
Country
Germany
Hosting
Fastly, Inc.
ASN
AS54113
TLS Cert
Let's Encrypt
External detection
urlscan.io
CleanGoogle Safe Browsing · OpenPhish · PhishTank · TweetFeed
Requests
Resources
Observables
Related websites
Report this phishing
Submit to blocklists
urlscan
VirusTotal
Whois
ipinfo
Greynoise