amazonpartsmercedes.gr - malicious URL scan, 22 Aug 2026
MalwareAnalyzer by Cyble scanned amazonpartsmercedes.gr and returned a malicious verdict (score 80), categorised as phishing. The page resolved to 172.67.163.98 on Cloudflare, Inc. in US. 10 domains and 9 IPs were contacted, over 29 HTTP requests. This is a point-in-time observation from 22 Aug 2026; the page may have changed since.
Scan result
- Verdict: malicious (score 80) · Confidence 86%
- Scanned URL:
https://amazonpartsmercedes.gr/ - Domain: amazonpartsmercedes.gr · IP: 172.67.163.98 · AS13335 · US
- Server: cloudflare
- HTTP status: 200 · text/html
- TLS issuer: C=US, O=Google Trust Services, CN=WE1 · valid to Nov 18 07: · subject CN=amazonpartsmercedes.gr
- HTTP requests captured: 29 · cookies set: 1 · outgoing links: 46
- Scan tier: standard · observed 2026-08-22 22:17:30 UTC
Antivirus & YARA (2 of 48 engines)
- YARA: delivr.to detections [yara]: DLV_HTML_Smuggling (page content)
- YARA: Stratosphere IPS [yara]: STRATO_Tor_Onion_C2 (page content)
Categories
- phishing
Why this verdict
- 2 antivirus/YARA engines flagged the page content: DLV_HTML_Smuggling, STRATO_Tor_Onion_C2
- Domain impersonates amazon (combosquat)
Detected technologies
- Cloudflare
- Cloudflare Insights
Contacted infrastructure
- 172.67.163.98 - AS13335 Cloudflare, Inc. (United States)
- 104.16.79.73 - AS13335 Cloudflare, Inc. (United States)
- 172.217.116.4 - AS15169 Google LLC (United States)
- 142.250.195.131 - AS15169 Google LLC (India)
Observed indicators
- amazonpartsmercedes.gr
- assets.mysite-now.com
- fonts.gstatic.com
- static.cloudflareinsights.com
- fonts.googleapis.com
- maps.googleapis.com
- fapi.mysite-now.com
- cdn.userway.org
- softexpert-projects.s3.eu-central-1.amazonaws.com
- api.userway.org
- 172.67.163.98
- 104.21.81.185
- 104.16.79.73
- 142.250.195.170
- 172.217.116.4
- 104.21.89.114
- 142.250.195.131
- 79.127.235.12
- 52.219.170.230
- https://amazonpartsmercedes.gr/
Questions about amazonpartsmercedes.gr
- Is amazonpartsmercedes.gr safe?
- No. MalwareAnalyzer scanned amazonpartsmercedes.gr on 22 Aug 2026 and returned a malicious verdict with a score of 80 out of 100, categorised as phishing. Treat it as hostile until it is re-checked.
- How was amazonpartsmercedes.gr checked?
- A static pass resolved DNS, captured TLS and headers and followed the redirect chain, and where the standard tier allows, a headless browser rendered the page and recorded every request. Egress is SSRF-locked. Signatures that matched only page text are weighted far below one that matched a served file, because a page documenting malware matches the same rules.
Scanned at the standard tier - see how URL scanning works.
Scan another URL · Latest analyzed threats · All scans of amazonpartsmercedes.gr
Scanned on MalwareAnalyzer by Cyble · Open interactive scan