www.basraamazon.com - malicious URL scan, 21 Aug 2026
MalwareAnalyzer by Cyble scanned www.basraamazon.com and returned a malicious verdict (score 98), categorised as phishing, credential-harvest, impersonating binance. The page resolved to 104.26.14.164 on Cloudflare, Inc. in US. The domain was registered 1187 days ago through NameCheap, Inc.. 7 domains and 8 IPs were contacted, over 118 HTTP requests. This is a point-in-time observation from 21 Aug 2026; the page may have changed since.
Scan result
- Verdict: malicious (score 98) · Confidence 100%
- Scanned URL:
https://www.basraamazon.com/ - Domain: www.basraamazon.com · IP: 104.26.14.164 · AS13335 · US
- Server: cloudflare
- Page title: BasraAmazon | Ecommerce
- HTTP status: 200 · text/html; charset=utf-8
- Registrar: NameCheap, Inc. · domain age 1187 days · created 2023-05-21
- TLS issuer: C=US, O=Google Trust Services, CN=WE1 · valid to Oct 11 06: · subject CN=basraamazon.com
- HTTP requests captured: 118 · cookies set: 2 · outgoing links: 348
- Scan tier: standard · observed 2026-08-21 15:14:18 UTC
Antivirus & YARA (2 of 47 engines)
- YARA: delivr.to detections [yara]: DLV_HTML_Smuggling (page content)
- YARA: JPCERT/CC [yara]: JPCERT_LODEINFO (page content)
Categories
- phishing
- credential-harvest
Why this verdict
- 2 antivirus/YARA engines flagged the page content: DLV_HTML_Smuggling, JPCERT_LODEINFO
- Domain impersonates amazon (combosquat)
- Credential-harvesting form
- Matches phishing-kit family "Binance / Crypto Exchange Kit"
Detected technologies
- Cloudflare
- PHP
- Cloudflare Insights
Contacted infrastructure
- 172.67.74.219 - AS13335 Cloudflare, Inc. (United States)
- 104.16.80.73 - AS13335 Cloudflare, Inc. (United States)
- 104.17.208.5 - AS13335 Cloudflare, Inc. (United States)
- 142.250.183.35 - AS15169 Google LLC (India)
Observed indicators
- www.basraamazon.com
- exo-ess.s3.amazonaws.com
- fonts.googleapis.com
- fonts.gstatic.com
- unpkg.com
- cdn.jsdelivr.net
- static.cloudflareinsights.com
- 104.26.14.164
- 172.67.74.219
- 104.18.0.22
- 142.251.222.234
- 104.16.80.73
- 52.217.136.89
- 104.17.208.5
- 142.250.183.35
- https://www.basraamazon.com/
- https://exo-ess.s3.amazonaws.com/uploads/all/drgWpait5xhmFsY3OJJWyNSmVlrx31Dy5MNTW84W.png
- https://fonts.googleapis.com/
- https://fonts.gstatic.com/
- https://fonts.googleapis.com/css2?family=Fira+Code:wght@300..700&family=Tajawal:wght@200;300;400;500;700;800;900&display=swap
Questions about www.basraamazon.com
- Is www.basraamazon.com safe?
- No. MalwareAnalyzer scanned www.basraamazon.com on 21 Aug 2026 and returned a malicious verdict with a score of 98 out of 100, categorised as phishing and credential-harvest. Treat it as hostile until it is re-checked.
- Does www.basraamazon.com belong to binance?
- No. This page claims the identity of binance but nothing establishes that binance operates it, which is what impersonation means here. Compare the certificate organisation and the registrant against the brand's real properties.
- How was www.basraamazon.com checked?
- A static pass resolved DNS, captured TLS and headers and followed the redirect chain, and where the standard tier allows, a headless browser rendered the page and recorded every request. Egress is SSRF-locked. Signatures that matched only page text are weighted far below one that matched a served file, because a page documenting malware matches the same rules.
Scanned at the standard tier - see how URL scanning works.
Scan another URL · Latest analyzed threats · All scans of www.basraamazon.com · Other binance phishing domains
Scanned on MalwareAnalyzer by Cyble · Open interactive scan