الانتقال إلى تقرير الأمان
Checked 09/08/2026 Ref 730D2DD1

MALICIOUS — CRITICAL

x-aml[.]ru

The domain x-aml.ru was created on 21 February 2026 and is currently listed as offline.

72/100 evidence score · Critical
VirusTotal
4/91
Blocklists
No stored match
التوفر
آخر نشاط معروف · HTTP 200
Report / Add Evidence Appeal this listing
2026-02-26 22:20 UTCآخر نشاط معروف · HTTP 200

Do not enter credentials, seed phrases, payment details, or personal information on this domain.

⚠️
تم الإبلاغ عن هذا النطاق باعتباره ضارًّا
محركات الأمان التي تبلغ عن اكتشاف: 4. توخي الحذر الشديد — لا تدخل بيانات الاعتماد أو المعلومات الشخصية.
Jump to section
ملخص التقرير

x-aml.ru — آخر نشاط معروف (HTTP 200). انتحال العلامة التجارية: Telegram; نوع الاحتيال: Crypto Scam. ملخص الأدلة: VirusTotal 4/91 (alphaMountain.ai, CRDF, Fortinet, Gridinsoft); Spamhaus DBL_SPAM; PhishDestroy score 72/100.

يبقى تحليل PhishDestroy AI المفصل أدناه باللغة الإنجليزية للحفاظ على السجل الجنائي الرقمي الأصلي.

Evidence Analysis

Ref 730D2DD1

x-aml.ru Safety Check — Telegram Impersonation Detected

The domain x-aml.ru was created on 21 February 2026 and is currently listed as offline.

The domain x-aml.ru was created on 21 February 2026 and is currently listed as offline. DNS resolution points to IP address 193.233.113.108, which belongs to AS205775 NEON CORE NETWORK LLC and is geolocated in Finland. The hosting infrastructure therefore originates from a Finnish network operator, but no further information about the underlying server environment is publicly disclosed. The site presented the page title “X-AML - Comprehensive AML Compliance Solutions for Crypto,” indicating a focus on anti‑money‑laundering services for cryptocurrency users, while the brand target is identified as Telegram. This combination suggests a crypto‑related brand‑impersonation campaign that leverages Telegram’s reputation to lure victims.

Security assessments show a Gridinsoft trust score of 0 / 100, reflecting an extremely low confidence rating. The domain is listed on a single security blocklist and has been blocked by the PhishDestroy mitigation service. VirusTotal analysis recorded detections from two of ninety‑three scanning engines, confirming that at least a minority of antivirus products recognize malicious activity associated with the domain. The SSL certificate carries an R10 rating, implying weak encryption or an otherwise untrusted certificate chain. Given the limited detection coverage and the offline status, the full payload or phishing page content has not been captured, leaving the exact user‑interaction flow uncertain.

Defenders should continue to monitor the IP address 193.233.113.108 for any re‑activation, enforce outbound filtering for connections to this host, and add x-aml.ru to internal blocklists. Network‑level alerts for TLS handshakes with the R10 certificate may help identify attempts to resurrect the site. Organizations using Telegram for official communications should educate users about unsolicited links promising AML compliance services, especially those that reference cryptocurrency or financial regulation.

Stored source results

Recorded verdicts and infrastructure observations for this domain.

VirusTotal
VirusTotal
4 det.
شهادة TLS
منتهية الصلاحية أو غير متحقق منها
العمر
6 mo
الحالة المرصودة
آخر نشاط معروف 200
PhishDestroy
قائمة الإتلاف
مُدرج
نطاق تغطية البيانات12 recorded checks
VirusTotal 4 / 91 URLQuery checked — no detections recorded PhishStats لم يتم التحقق منها OTX no community references رادار CF no data URLScan capture التقرير المخزن URLScan verdict اكتمل التحليل حجب عناوين DNS لم يتم التحقق منها TLS منتهية الصلاحية أو غير متحقق منها WHOIS 6 mo old لقطة شاشة 3 captures · 3 sources سلسلة إعادة التوجيه لم يتم التحقيق فيها

مسار الاستجابة للتهديدات Pipeline

الاكتشاف
Checks
Reports
التوفر
9/11

حالة قوائم الحظر العامة

لقطة محفوظة

معلومات النطاق

النطاق
URLScan Verdict اكتمل التحليل score 0 report ↗
Telegram IoCs 1 extracted https://t.me/dimazapex
الخادم / ASN nginx/1.18.0 (Ubuntu) · AS215826 Partner-Hosting-LTD Partner Hosting LTD, GB
سمعة عنوان IP abuse score 0/100 0 reports checked 01/08/2026
عنوان IP 193.233.113.108 FI
الموقع الجغرافيFI Helsinki, FI
الشبكةAS215826 · AS205775 NEON CORE NETWORK LLC
التسجيلتم إنشاؤه 21/02/2026 (169d)
Elapsed Since First Report 42 days
ما الذي نحتسبه Raw elapsed time since the first stored abuse report. It is not a registrar response-time measurement. Latest observed status: آخر نشاط معروف.
ما يحتويه كل تقرير قد تشير سجلات التقارير الصادرة المخزنة إلى الأدلة المتاحة في ذلك الوقت، مثل أحكام البائعين أو بيانات التسجيل أو تفاصيل الاستضافة أو التصنيفات أو لقطات الشاشة. لا تستنتج هذه الصفحة الحمولة الدقيقة التي تم تسليمها أو استلامها أو إقرارها أو الإجراء الذي اتخذه المستلم.
حالة HTTP200
التفاصيل الفنيةDNS، أسماء المجال البديلة (SAN) في بروتوكول SSL، الطوابع الزمنية
تاريخ أول اكتشاف26/02/2026
DOM Analysisanalyzed 24/03/2026score 71/1001 brand signal
IoC Extractionscanned 01/08/20260 wallet · 1 Telegram IoC
عنوان الصفحة
X-AML - Comprehensive AML Compliance Solutions for Crypto
Impersonates
Telegram
شهادة TLS
منتهية الصلاحية أو غير متحقق منها · صادرة عن R10
الإبلاغ عن هذا النطاق أرسل الأدلة وساعد في حماية الآخرين

تحليل VirusTotal

4 / قام موردو الأمان 91 بوضع علامة على هذا المجال
View on VT
Last analyzed Previous stored snapshot: 2 detections
alphaMountain.ai
CRDF
Fortinet
Gridinsoft
الأدلة والتقارير الخارجيةIndependent lookups and source reports
Victim safety and official reportingImmediate actions and verified reporting channels
If credentials were compromised, report immediately. Do not engage with recovery scammers.

إذا أدخلت بيانات اعتماد الحساب أو المعلومات الشخصية أو معلومات الدفع أو قمت بتنزيل ملف من هذا النطاق، فاتخذ إجراءً فوريًا. فيما يلي موارد لمساعدتك في الإبلاغ عن الحادث وحماية نفسك.

اليوروبول
ابحث عن قناة التقارير الرسمية لبلدك في الاتحاد الأوروبي
National police directory
احذروا من المحتالين الذين يزعمون أنهم يساعدون في استرداد الأموال! قد يتصل المجرمون بالضحايا مرة أخرى بينما يتظاهرون بأنهم محققون أو محامون أو وكلاء استرداد. لا تدفع رسومًا مقدمة أو تشارك بيانات الاعتماد. تعرف على المزيد حول الاحتيال في مجال التعافي →

أبلغ السلطات المحلية

حدد بلدك للحصول على الاتصالات الرسمية المتعلقة بالجرائم الإلكترونية أو إنشاء مسودة شكوى →.

دليل 97 دولة
المسودة بمساعدة الذكاء الاصطناعي - تتم معالجة تفاصيل الحادث بواسطة موفر الذكاء الاصطناعي قم بمراجعتها وتقديمها بنفسك
تضمين هذا التقريرRead-only HTML widget
HTML · IFRAME

تضمين هذا التقرير

شارك هذه المعلومات الاستخباراتية المتعلقة بالتهديدات على موقعك الإلكتروني أو مدونتك

embed.html
<iframe
  src="https://phishdestroy.io/ar/embed/domain/x-aml.ru"
  title="PhishDestroy threat report for x-aml.ru"
  width="100%" height="320"
  loading="lazy"
  referrerpolicy="no-referrer"
  sandbox="allow-same-origin allow-popups allow-popups-to-escape-sandbox"
  style="border:0;border-radius:12px;max-width:100%"
></iframe>