amazon.wcsigns.com - URL scan, 22 Aug 2026
MalwareAnalyzer by Cyble scanned amazon.wcsigns.com and returned a unknown verdict (score 6), categorised as credential-harvest. The page resolved to 65.60.63.98 on Internap Holding LLC in US. The domain was registered 5286 days ago through NameCheap, Inc.. 4 domains and 4 IPs were contacted, over 39 HTTP requests. This is a point-in-time observation from 22 Aug 2026; the page may have changed since.
Scan result
- Verdict: unknown (score 6) · Confidence 12%
- Scanned URL:
https://amazon.wcsigns.com/login - Domain: amazon.wcsigns.com · IP: 65.60.63.98 · AS32475 · US
- Server: WWW Server/1.1
- Page title: Login
- HTTP status: 200 · text/html; charset=utf-8
- Registrar: NameCheap, Inc. · domain age 5286 days · created 2012-03-01
- TLS issuer: C=US, O=Let's Encrypt, CN=YE2 · valid to Sep 15 21: · subject CN=amazon.wcsigns.com
- HTTP requests captured: 39 · cookies set: 2 · outgoing links: 9
- Scan tier: standard · observed 2026-08-22 04:07:09 UTC
Antivirus & YARA (0 of 48 engines)
No engine flagged this page's content.
Categories
- credential-harvest
Why this verdict
- Credential-harvesting form
- Valid TLS, no impersonation or off-origin credential post
Detected technologies
- jQuery
Contacted infrastructure
- 65.60.63.98 - AS32475 Internap Holding LLC (United States)
- 142.250.195.163 - AS15169 Google LLC (India)
Observed indicators
- amazon.wcsigns.com
- ajax.googleapis.com
- fonts.googleapis.com
- fonts.gstatic.com
- 65.60.63.98
- 142.251.222.234
- 142.250.195.138
- 142.250.195.163
- https://amazon.wcsigns.com/login
- https://amazon.wcsigns.com/files/subscribers/8d3c8c8f-e116-4954-91cf-64814cdc8e6e/sites/2c0c0000-569f-0050-018a-08d93587d787/favicon.ico?stamp=637636885708901427
- https://ajax.googleapis.com/ajax/libs/jquery/3.6.0/jquery.min.js
- https://amazon.wcsigns.com/Scripts/jquery-3.6.0.min.js
- https://amazon.wcsigns.com/Content/w2pclient.min.css?stamp=20260822020933
- https://amazon.wcsigns.com/Content/css/checkout/checkout.min.css?stamp=20260822020933
- https://amazon.wcsigns.com/layout/skins/library/lib/css/library.min.css?v=2026.8.12.8&stamp=20260822020933
- https://amazon.wcsigns.com/layout/skins/library/base_skin/responsiveEnder/base_skin.min.css?v=2026.8.12.8&stamp=20260822020933
- https://amazon.wcsigns.com/layout/skins/5939bf53-cc3d-4c42-86ab-0e8b21105403/layout.css?v=2026.8.12.8&stamp=20260822020933
- https://amazon.wcsigns.com/
- https://amazon.wcsigns.com/files/subscribers/8d3c8c8f-e116-4954-91cf-64814cdc8e6e/sites/2c0c0000-569f-0050-018a-08d93587d787/logo_2c0c0000-569f-0050-018a-08d93587d787_large.png?stamp=638109553075912349
- https://amazon.wcsigns.com/cart
Questions about amazon.wcsigns.com
- Is amazon.wcsigns.com safe?
- The scan of amazon.wcsigns.com on 22 Aug 2026 reached no verdict either way (score 6). Too little was captured to judge it, which is an unknown rather than a pass.
- How was amazon.wcsigns.com checked?
- A static pass resolved DNS, captured TLS and headers and followed the redirect chain, and where the standard tier allows, a headless browser rendered the page and recorded every request. Egress is SSRF-locked. Signatures that matched only page text are weighted far below one that matched a served file, because a page documenting malware matches the same rules.
Scanned at the standard tier - see how URL scanning works.
Scan another URL · Latest analyzed threats · All scans of amazon.wcsigns.com
Scanned on MalwareAnalyzer by Cyble · Open interactive scan