amlserviceusdt[.]com
فحص التصيد والأمان للنطاق amlserviceusdt.com
“AML Check”
amlserviceusdt.com — المحتوى غير متوفر (HTTP 502). انتحال العلامة التجارية: Csgo; نوع الاحتيال: Crypto Scam. ملخص الأدلة: VirusTotal 3/93 (Fortinet, G-Data, Gridinsoft); URLQuery 1 alert; URLScan malicious verdict; 1 external blocklist match (ScamSniffer); PhishDestroy score 65/100.
يبقى تحليل PhishDestroy AI المفصل أدناه باللغة الإنجليزية للحفاظ على السجل الجنائي الرقمي الأصلي.
This domain, amlserviceusdt.com, was registered on 21 February 2026 and is presently listed as offline. DNS resolution points to the IPv4 address 194.87.110.74, which belongs to AS48347 JSC Mediasoft ekspert in Russia. The HTTP response that was observed before the site was taken down returned a page title of “AML Check”, a generic term that does not reference the targeted brand. The domain is explicitly linked to a brand‑impersonation campaign against the popular game “csgo”, as indicated by the intelligence that it impersonates csgo. The activity has been categorized as a crypto‑scam, suggesting that the site likely attempted to lure victims into providing cryptocurrency‑related information or payments.
Detection evidence shows the domain appears on two security blocklists, specifically PhishDestroy and ScamSniffer, confirming that multiple threat‑intelligence feeds have flagged it. VirusTotal analysis recorded three positive detections out of ninety‑three scanning engines, reinforcing the malicious assessment. The SSL certificate associated with the site is identified as “R13”, which is atypical for legitimate services and further reduces trust. The risk level has been assigned as elevated, reflecting the combination of brand impersonation, cryptocurrency focus, and the presence on reputable blocklists. While the available data confirms the malicious intent, the lack of a live site limits deeper content inspection; no screenshots, login forms, or payload samples have been captured.
Consequently, the exact phishing kit or payment workflow remains unknown. Defenders should continue to block the domain and the associated IP address at network perimeters, add the host to internal threat‑intel feeds, and monitor for any future re‑registration of the same name or similar sub‑domains. Ongoing observation of the AS48347 range is advised, as it may host additional malicious infrastructure.
استخبارات أمن الشبكات
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| Quad9 DNS | healthandbodies.com |
malicious | Sinkholed |
مسار الاستجابة للتهديدات Pipeline
حالة قوائم الحظر العامة
تحليل VirusTotal
الأدلة والتقارير الخارجية
هل تأثرت بهذا الموقع؟
إذا أدخلت بيانات اعتماد الحساب أو المعلومات الشخصية أو معلومات الدفع أو قمت بتنزيل ملف من هذا النطاق، فاتخذ إجراءً فوريًا. فيما يلي موارد لمساعدتك في الإبلاغ عن الحادث وحماية نفسك.
أبلغ السلطات المحلية
حدد بلدك للحصول على الاتصالات الرسمية المتعلقة بالجرائم الإلكترونية أو إنشاء مسودة شكوى →.
تحقق من أي نطاق
تحليل التهديدات باستخدام قائمة الحظر المخزنة، وWHOIS، وDNS، وأدلة الفحص العامة
امسح الآنالإبلاغ عن محاولة تصيد احتيالي
أرسل النطاقات المشبوهة إلى قاعدة بيانات التهديدات الخاصة بنا — ساهم في حماية المجتمع
إبلاغتحديثات فورية حول التهديدات
تقارير التصيد الاحتيالي الأخيرة وتغييرات التوفر الملحوظة
مراقبةابقَ على اطلاع، وابقَ آمنًا
راقب التهديدات في الوقت الفعلي أو اعترض على هذا الإدراج إذا كنت تعتقد أنه إنذار كاذب