Phishing detection: wetransferswiftserverr.edgeone.dev
WeTransfer Investigate
Domain
wetransferswiftserverr.edgeone.dev1 CT host on apex
IP
43.174.247.29
URL
https://wetransferswiftserverr.edgeone.dev
Cert
DigiCert Secure Site OV G2 TLS CN RSA4096 SHA256 2022 CA1
Phishunt analysis Beta
21
low suspicionheuristic risk score · not a probability
Why?
- +5.3 Keyword match
- +3.0 OpenPhish
- +2.2 Country mismatch
- +1.8 ASN reputation
- +1.7 Shared IP cluster
- +1.1 Cert reuse
- +1.1 No CSP header
- +1.1 No HSTS header
- +1.0 Site cluster
- +0.7 Unrecognised DNS provider
- +0.6 Long domain
- +0.6 Login text in screenshot
- +0.6 Suspicious TLD
- +0.1 Deep subdomain
17 signals fired · detector v3.0.0
AI analysis AIBeta
Credential harvesting
WeTransfer impersonation site hosted on an edgeone.dev subdomain mimicking the file-sharing service to harvest credentials. IP and certificate clustering ties it to broader phishing infrastructure. Confirmed malicious by OpenPhish.
OpenPhishKeyword matchLong domain
AI-generated from stored detector signals - the AI never visited the site. · 2026-09-12 · confidence 78%
Domain & Network
Whois
Registrar
MarkMonitor Inc.
Network
Country
Singapore
Hosting
ACE
ASN
AS139341
External detection
OpenPhish
CleanGoogle Safe Browsing · PhishTank · TweetFeed · urlscan.io
Requests
Resources
Observables
Related websites
Report this phishing
Submit to blocklists
urlscan
VirusTotal
Whois
ipinfo
Greynoise