الانتقال إلى تقرير الأمان
⚠️
تم الإبلاغ عن هذا النطاق باعتباره ضارًّا
محركات الأمان التي تبلغ عن اكتشاف: 9. توخي الحذر الشديد — لا تدخل بيانات الاعتماد أو المعلومات الشخصية.
أمن المجال وذكاء التهديدات

check[.]safeaml[.]icu

“AML Check — Мониторинг криптотранзакций”

حكم التهديد حرجة 77/100 درجة الأدلة
التوفر المحتوى غير متوفر لم يكن المحتوى متاحًا في الملاحظة الأخيرة
VirusTotal detections: 9 (vendor total unavailable) انتحال العلامة التجارية: Across
24/01/2026 Across 1 Report Sent CDN

ملخص الأدلة

حرج
Evidence score
77/100

On 24 July 2026, check.safeaml.icu was observed as an offline site associated with a brand‑impersonation investment scam. The domain was registered on 21 February 2026 through PDR Ltd. d/b/a PublicDomainRegistry.com and uses Cloudflare’s DNS with the authoritative nameservers liberty.ns.cloudflare.com and patrick.ns.cloudflare.com. DNS resolution returns the IPv6 address 2a06:98c1:3120::3, which belongs to AS13335 Cloudflare, Inc. and is geolocated to the United States. No TLS certificate was presented when the site was reachable, indicating the lack of HTTPS protection.

The page title returned by the server reads "AML Check — Мониторинг криптотранзакций", suggesting a focus on cryptocurrency transaction monitoring, consistent with the reported scam type of "Investment Scam". VirusTotal records show that nine of ninety‑five scanning engines flagged the domain, and the site appears on a single external blocklist. PhishDestroy has also listed the domain as blocked. The risk rating assigned by the reporting system is elevated.

Current evidence does not reveal any active payload, credential‑harvesting form, or redirection chain, and the site’s HTTP response code is not available because the service is offline. Analysts should continue to monitor the domain for re‑activation, enforce blocking at network perimeter and endpoint security solutions, and consider adding the IPv6 address to threat‑intel feeds. Further investigation of any future HTTP responses, TLS fingerprints, or associated malware would be required to fully characterize the malicious infrastructure.

لقطة الأدلة المرسلة

أُرسل
سجلات الدفتر
1
معرّف القضية
PD-20260124-B81DAB
ملف PDF
دليل PDF
النص الكامل للدليل
Policy Violations:
Acceptable Use Policy (AUP): The domain check.safeaml.icu is engaged in phishing activities, which directly contravenes your AUP prohibiting illegal activities, fraud, and deception.
Terms of Service (TOS): The use of this domain for fraudulent purposes constitutes a violation of your TOS, which reserves the right to suspend or terminate services for such violations.
Applicable Laws (CN):
Cybersecurity Law of the People's Republic of China: This law prohibits the use of information networks to engage in illegal activities, including phishing and fraud.
Criminal Law of the People's Republic of China (Article 285): This article addresses computer fraud, making it illegal to deceive others for financial gain through electronic means.
Regulations on the Administration of Internet Information Services: These regulations impose strict penalties for the dissemination of false information and fraudulent activities online.
Regulatory Note: Failure to take appropriate action against this domain may result in regulatory scrutiny and potential legal consequences for non-compliance with applicable laws and your own policies.
VirusTotal
VirusTotal
9 det.
الحالة المرصودة
المحتوى غير متوفر HTTP 502
PhishDestroy
قائمة الإتلاف
مدرج
Reports Sent
1

Data Coverage

VirusTotal 9 detections · vendor total unavailable URLQuery checked — no detections recorded PhishStats لم يتم التحقق منها OTX no community references رادار CF scan completed URLScan capture التقرير المخزن URLScan verdict التقييم غير متاح حجب عناوين DNS لم يتم التحقق منها TLS لا توجد بيانات للشهادة WHOIS not parsed لقطة شاشة 3 captures · 3 sources سلسلة إعادة التوجيه لم يتم التحقيق فيها

مسار الاستجابة للتهديدات Pipeline

الاكتشاف
Checks
Reports
التوفر
12/12

تغطية قوائم الحظر

١٠ مصادر خارجية مراقبة · لقطة محفوظة 11/08/2026

١٠ مصادر خارجية مراقبة لا تطابق

المخطط الزمني للاكتشاف

  1. Cloudflare Radar

    تم حفظ فحص Cloudflare Radar · فتح الفحص

لقطة محفوظة

عنوان الصفحة
AML Check — Мониторинг криптотранзакций
Impersonates
Across

معلومات النطاق

النطاق
الخادم / ASN cloudflare · AS13335 CLOUDFLARENET - Cloudflare, Inc., US
IP Context Cloudflare shared edge origin IP hidden لا تُنسب سمعة Edge-IP إلى هذا المجال.
Registrar (base domain) PDR IN(IN)
جهة الإبلاغ عن إساءة الاستخدامchain.gpt.media@gmail.com, abuse@publicdomainregistry.com
البحث في قاعدة بيانات WHOISICANN RDAP لـ safeaml.icu →
عنوان IP 2a06:98c1:3120::3 CDN
الموقع الجغرافيUS San Francisco, US
الشبكةAS13335 · Cloudflare, Inc.
يتم إخفاء عنوان IP الأصلي خلف وكيل CDN. تحتوي نتائج IP العكسي لعنوان الحافة على مستأجرين غير مرتبطين؛ يتطلب العثور على المصدر نظام أسماء النطاقات السلبي أو بيانات شفافية الشهادة.
Registration (base domain)safeaml.icu · Expires 14/01/2027
حالة HTTP502 Error
الوقت حتى أول تعذّر للوصول 29 days
ما الذي نحتسبه الوقت المنقضي من أول تقرير عن إساءة الاستخدام المخزن إلى الملاحظة الأولى بأن المحتوى غير متوفر. هذا لا يحدد السبب.
ما يحتويه كل تقرير قد تشير سجلات التقارير الصادرة المخزنة إلى الأدلة المتاحة في ذلك الوقت، مثل أحكام البائعين أو بيانات التسجيل أو تفاصيل الاستضافة أو التصنيفات أو لقطات الشاشة. لا تستنتج هذه الصفحة الحمولة الدقيقة التي تم تسليمها أو استلامها أو إقرارها أو الإجراء الذي اتخذه المستلم.
التفاصيل التقنيةDNS وأسماء TLS والطوابع الزمنية
تاريخ أول اكتشاف24/01/2026
DOM Analysisanalyzed 24/03/2026DOM analysis score 10/1001 brand signal
Submitted URLhttps://check.safeaml.icu/
خوادم الأسماءliberty.ns.cloudflare.compatrick.ns.cloudflare.com
رصد TLSفُحص في 15/03/2026
نطاق SHORTDOT · أدلة عامة .icu

ShortDot zone evidence

The linked repository preserves daily zone observations across seven ShortDot-operated TLDs, including registration volume and abuse-related indicators. This registry context is supporting background and is not an independent detection for the domain in this report.

ShortDot SA · Luxembourg 7 مناطق · أدلة المناطق الكاملة تُحدّث يوميًا افتح مستودع أدلة ShortDot
ICANN OVERSIGHT Registration: safeaml.icu

الاعتماد وسياق RAA

Registrar accreditation and DNS abuse obligations

For the registrable domain safeaml.icu behind this subdomain, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.

Accreditation is a contract, not a safety certification.

RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.

Accountability draft لا يُرسل أي شيء تلقائياً.
الإبلاغ عن هذا النطاق أرسل الأدلة وساعد في حماية الآخرين

تحليل VirusTotal

9 detections recorded · vendor total unavailable
View on VT
Last analyzed
BitDefender
CRDF
CyRadar
Fortinet
G-Data
Lionic
SOCRadar
سوفوس
Trustwave

هل تأثرت بهذا الموقع؟

If credentials were compromised, report immediately. Do not engage with recovery scammers.

إذا أدخلت بيانات اعتماد الحساب أو المعلومات الشخصية أو معلومات الدفع أو قمت بتنزيل ملف من هذا النطاق، فاتخذ إجراءً فوريًا. فيما يلي موارد لمساعدتك في الإبلاغ عن الحادث وحماية نفسك.

اليوروبول
ابحث عن قناة التقارير الرسمية لبلدك في الاتحاد الأوروبي
National police directory
احذروا من المحتالين الذين يزعمون أنهم يساعدون في استرداد الأموال! قد يتصل المجرمون بالضحايا مرة أخرى بينما يتظاهرون بأنهم محققون أو محامون أو وكلاء استرداد. لا تدفع رسومًا مقدمة أو تشارك بيانات الاعتماد. تعرف على المزيد حول الاحتيال في مجال التعافي →

أبلغ السلطات المحلية

حدد بلدك للحصول على الاتصالات الرسمية المتعلقة بالجرائم الإلكترونية أو إنشاء مسودة شكوى →.

دليل 97 دولة
المسودة بمساعدة الذكاء الاصطناعي - تتم معالجة تفاصيل الحادث بواسطة موفر الذكاء الاصطناعي قم بمراجعتها وتقديمها بنفسك

تحقق من أي نطاق

تحليل التهديدات باستخدام قائمة الحظر المخزنة، وWHOIS، وDNS، وأدلة الفحص العامة

امسح الآن

الإبلاغ عن محاولة تصيد احتيالي

أرسل النطاقات المشبوهة إلى قاعدة بيانات التهديدات الخاصة بنا — ساهم في حماية المجتمع

إبلاغ

تحديثات فورية حول التهديدات

تقارير التصيد الاحتيالي الأخيرة وتغييرات التوفر الملحوظة

مراقبة

ابقَ على اطلاع، وابقَ آمنًا

راقب التهديدات في الوقت الفعلي أو اعترض على هذا الإدراج إذا كنت تعتقد أنه إنذار كاذب

تحديثات فورية حول التهديدات الاعتراض على هذا الإعلان

أدوات خارجية

HTML · IFRAME

تضمين هذا التقرير

شارك هذه المعلومات الاستخباراتية المتعلقة بالتهديدات على موقعك الإلكتروني أو مدونتك

embed.html
<iframe
  src="https://phishdestroy.io/ar/embed/domain/check.safeaml.icu"
  title="PhishDestroy threat report for check.safeaml.icu"
  width="100%" height="320"
  loading="lazy"
  referrerpolicy="no-referrer"
  sandbox="allow-same-origin allow-popups allow-popups-to-escape-sandbox"
  style="border:0;border-radius:12px;max-width:100%"
></iframe>

رسالة شكر صادقة جداً

منشئ مسودة ساخرة

المستلم
سياق الرسوم

مسودة ساخرة. أرقام الرسوم تقديرية، ولا ندّعي نسبتها بدقة إلى هذا النطاق.