Phishing detection: apisimpatik-google-amp.pages.dev

Google
https://apisimpatik-google-amp.pages.dev Access site
Screenshot
No screenshot available yet Captured automatically on the next refresh cycle
Investigate
Domain apisimpatik-google-amp.pages.dev1 CT host on apex
URL https://apisimpatik-google-amp.pages.dev
Cert Let's Encrypt
Phishunt analysis Beta
25 low suspicionheuristic risk score · not a probability
Why?
  • +5.3 Keyword match
  • +5.1 Site cluster
  • +5.1 urlscan.io
  • +3.4 Shared IP cluster
  • +1.1 ASN reputation
  • +1.1 No CSP header
  • +1.1 No HSTS header
  • +0.7 Brand in cert SAN
  • +0.6 Long domain
  • +0.6 Suspicious TLD
  • +0.5 Young certificate
  • +0.3 Free CA
  • +0.2 Hyphens
  • +0.1 External scripts
  • +0.1 Deep subdomain
18 signals fired · detector v3.0.0
AI analysis AIBeta
Credential harvesting

Impersonates Google AMP on a Cloudflare Pages free-hosting domain, with the Google brand confirmed in the TLS certificate SAN. Flagged malicious by urlscan and abusing PaaS infrastructure to evade takedowns, likely harvesting Google account credentials.

Brand in cert SANurlscan.ioPaaS host
AI-generated from stored detector signals - the AI never visited the site. · 2026-08-22 · confidence 72%
Domain & Network
Whois
Registrar CloudFlare, Inc.
Network
Country United StatesUnited States
ASN AS13335
TLS Cert Let's Encrypt
External detection urlscan.io
CleanGoogle Safe Browsing · OpenPhish · PhishTank · TweetFeed
Report this phishing
PaaS platform Cloudflare Pages
Registrar CloudFlare, Inc.

Tracked from 2026-08-22 16:56 UTC  ·  Last refreshed 2026-08-23 15:30 UTC