aml-rank[.]com
“AML Check”
This domain is flagged as an elevated-risk generic phishing threat designed to mimic anti-money laundering (AML) verification portals. Analysis indicates the infrastructure is engineered to harvest credentials or distribute fraudulent compliance requests, a tactic commonly observed in financial sector impersonation schemes. The domain exhibits multiple high-confidence indicators of malicious intent, warranting immediate caution for users and organizations in regulated industries. Infrastructure analysis reveals the following technical indicators: the domain was registered on March 28, 2026, through Metaregistrar BV, a registrar frequently associated with high-risk registrations. It resolves to the IP address 172.67.147.173, a host with a history of hosting phishing content. Detection metrics show 12 out of 95 security vendors on a major threat intelligence platform flagged the domain as malicious. The domain appears on one security blocklist and was identified in a single threat intelligence pulse on a collaborative threat-sharing platform. Additionally, it has been actively blocked by at least one security provider, further corroborating its malicious classification. The domain is currently offline, which may indicate takedown efforts or a temporary cessation of operations by the threat actor. Mitigation steps specific to this threat type include immediate blocking of the domain and its associated IP address (172.67.147.173) at the network perimeter. Organizations should implement strict email filtering rules to quarantine messages containing references to aml-rank.com or similar AML-themed domains. Employees in compliance, finance, and legal departments should be briefed on the risks of fake AML verification portals, emphasizing the importance of verifying requests through official channels. Security teams are advised to monitor for lateral movement or credential misuse in cases where users may have interacted with the domain. Proactive threat hunting should focus on logs containing the domain name, IP address, or related indicators to identify any prior compromise. Given the domain's registration date in the future (2026), this anomaly should be treated as a red flag for fraudulent activity.
سجل البلاغ المرسل
لقطة الأدلة المرسلة
- أُرسل
- سجلات الدفتر
- 1
- معرّف القضية
PD-20260328-554339- عنوان الصفحة الملتقطة
- AML Check
- ملف PDF
- دليل PDF
الأساس القانوني
النص الكامل للدليل
Illegal Activities: Active phishing operation targeting victims
Fraud & Deception: Impersonation of legitimate services
Identity Theft: Collection of credentials under false pretenses
Applicable Laws (Unknown):
International Anti-Cybercrime Regulations
Budapest Convention on Cybercrime
Universal Fraud Prevention Laws
Phishing activities violate international cybercrime conventions and Unknown's domestic fraud laws.
Action Required: This evidence-backed report demonstrates clear violations requiring suspension per your policies. Continued hosting exposes your organization to regulatory scrutiny and potential legal liability.
استخبارات أمن الشبكات
مسار الاستجابة للتهديدات Pipeline
تغطية قوائم الحظر
10 مصادر · تمت المزامنة في 10/08/2026
المخطط الزمني للاكتشاف
الملاحظات المحفوظة بترتيب زمني.
-
VirusTotal
VirusTotal: 11 ← 12
لقطة محفوظة
معلومات النطاق
التفاصيل التقنيةDNS وأسماء TLS والطوابع الزمنية
ICANN OVERSIGHT
الاعتماد وسياق RAA
الاعتماد وسياق RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
الاستخبارات الجنائية الرقمية
تحليل VirusTotal
تحليل أداء الموقع
Google PageSpeed Insights — mobile performance audit of aml-rank.com · checked Jun 26, 2026
هل تأثرت بهذا الموقع؟
إذا أدخلت بيانات اعتماد الحساب أو المعلومات الشخصية أو معلومات الدفع أو قمت بتنزيل ملف من هذا النطاق، فاتخذ إجراءً فوريًا. فيما يلي موارد لمساعدتك في الإبلاغ عن الحادث وحماية نفسك.
أبلغ السلطات المحلية
حدد بلدك للحصول على الاتصالات الرسمية المتعلقة بالجرائم الإلكترونية أو إنشاء مسودة شكوى →.
تحقق من أي نطاق
تحليل التهديدات باستخدام قائمة الحظر المخزنة، وWHOIS، وDNS، وأدلة الفحص العامة
امسح الآنالإبلاغ عن محاولة تصيد احتيالي
أرسل النطاقات المشبوهة إلى قاعدة بيانات التهديدات الخاصة بنا — ساهم في حماية المجتمع
إبلاغتحديثات فورية حول التهديدات
تقارير التصيد الاحتيالي الأخيرة وتغييرات التوفر الملحوظة
مراقبةابقَ على اطلاع، وابقَ آمنًا
راقب التهديدات في الوقت الفعلي أو اعترض على هذا الإدراج إذا كنت تعتقد أنه إنذار كاذب