# PhishDestroy threat dossier — address-track.com ================================================================ Fetched: 2026-07-25 06:30:51 UTC Canonical: https://phishdestroy.io/domain/address-track.com/ ## VERDICT ---------------------------------------------------------------- TAKEN DOWN (neutralised) Composite threat score: 82/100 (PhishDestroy scoring — see methodology below) Scam classification: Crypto Scam ## DETECTION EVIDENCE ---------------------------------------------------------------- VirusTotal: 11/93 security vendors flagged this domain Flagging vendors: alphaMountain.ai, BitDefender, CRDF, CyRadar, G-Data, Lionic, Seclookup, SOCRadar, Sophos, Trustwave, Webroot Public blocklists: listed on 3 independent blocklists Victim re-reports (public form): 1 ## INFRASTRUCTURE ---------------------------------------------------------------- IP address: 95.181.213.148 (RU, Moscow) ASN: ASAS33842 Citytelecom LLC Hosting org: AS33842 Citytelecom LLC Registrar: Dominet (HK) Limited Nameservers: ["ns71.cloudns.net", "ns72.cloudns.com", "ns73.cloudns.net", "ns74.cloudns.uk"] Registered: 2026-02-21 Expires: 2026-11-06 Page title: AMLBot - Comprehensive Crypto Compliance Solution | Free AML Crypto Check HTTP response: 200 ## TLS CERTIFICATE ---------------------------------------------------------------- Issuer: ZeroSSL GmbH / ZeroSSL RSA DV SSL CA 2 Expires: 2026-09-02 Status: INVALID chain Fingerprint: 1c616116578ff5be56f43fde542898f5707127ca9c3c5bd7c0dc848380e9fe9a Subject Alternative Names (related infrastructure — often same operator): - www.address-track.com ## ABUSE-REPORT HISTORY (evidence of registrar non-response) ---------------------------------------------------------------- Status: CLOSED — no report required. This domain was neutralised before the abuse-report cycle could be dispatched — either the hosting provider / registrar suspended it on their own, the DNS went dead, or the operator abandoned the infrastructure. PhishDestroy keeps the evidence bundle on file for audit but no formal notice was sent. ## TIMELINE ---------------------------------------------------------------- Domain registered: 2026-02-21 (per WHOIS / CT — may reflect a renewal or transfer date, not first-ever registration) First detected: 2026-02-25 02:39:27 UTC (by PhishDestroy tracker) Earliest abuse rec: 2026-01-24 19:01:11 UTC — PREDATES current WHOIS registration; retained from a previous registration cycle of the same domain name Last verified: 2026-07-25 03:54:31 UTC Neutralised: 2026-05-02 12:00:39 UTC Current status: taken down (registrar suspended or DNS dead) Note: one or more events above predate the WHOIS creation date. This typically means the same domain name was previously registered, detected, dropped, and then re-registered by a new party. PhishDestroy preserves the full historical record for operator-attribution research even when the underlying infrastructure changes hands. ## EXTERNAL CORROBORATION (third-party evidence) ---------------------------------------------------------------- URLScan.io: https://urlscan.io/result/019bf0bc-28d6-766e-beda-ad6657c21328/ Wayback Machine: https://web.archive.org/web/*/address-track.com crt.sh CT logs: https://crt.sh/?q=%25.address-track.com Google transparency: https://transparencyreport.google.com/safe-browsing/search?url=address-track.com AlienVault OTX: https://otx.alienvault.com/indicator/domain/address-track.com URLhaus: https://urlhaus.abuse.ch/host/address-track.com/ ## ANALYST NARRATIVE ---------------------------------------------------------------- [Generated: 2026-06-18 18:40:44 UTC — narrative may predate facts above. Treat fields in TIMELINE / DETECTION EVIDENCE / INFRASTRUCTURE as authoritative if they differ from the prose below.] address-track.com: Confirmed AML Scam Impersonation The domain address-track.com has been identified as a high-risk phishing site engaged in brand impersonation of AMLBot, a crypto compliance solution, to perpetrate an AML scam. This threat is specifically designed to deceive users into believing they are interacting with a legitimate AML checking service, thereby stealing sensitive information or cryptocurrency assets. Technical analysis reveals that address-track.com was flagged by 11 out of 95 security vendors on VirusTotal, indicating broad recognition of its malicious nature. The domain was registered on February 21, 2026, through Dominet (HK) Limited, and resolves to the IP address 95.181.213.148. It appears on three security blocklists, and notably, it lacks an SSL certificate, which is a red flag for any site handling sensitive data. Google Safe Browsing status is not explicitly mentioned but the high VT score and blocklist presence suggest it was likely flagged. As of the latest intelligence, the site has been taken offline, mitigating immediate risk. However, users should remain cautious as similar domains may emerge. PhishDestroy recommends avoiding any unsolicited links to AML checking services and verifying URLs directly with official sources. Users who interacted with this site should monitor their accounts for suspicious activity and change credentials if any were entered. The remaining risk is low due to the takedown, but awareness is key to preventing future incidents. ## EVIDENCE HASHES ---------------------------------------------------------------- Favicon MD5: 00767150a6097e0507aeff40684d04dd TLS cert SHA-256: 1c616116578ff5be56f43fde542898f5707127ca9c3c5bd7c0dc848380e9fe9a ## SCORING METHODOLOGY ---------------------------------------------------------------- Composite score is NOT derived from VirusTotal alone. PhishDestroy aggregates: - VirusTotal positive ratio - Public blocklist consensus (MetaMask, ScamSniffer, OpenPhish, PhishTank, URLhaus, CryptoFirewall, SEAL, Polkadot, Enkrypt, Phishunt, DiscordPhishing, PhishingDB) - Cloaking detection (HTTP 666 or rendering delta between bot and real visitor) - DNS-filter consensus (Quad9, CleanBrowsing, NextDNS, AdGuard, Cloudflare, etc.) - AlienVault OTX pulses + Cloudflare Radar + Google Safe Browsing - URLScan / URLQuery verdicts - Brand-impersonation heuristics (DOM analysis of forms, logos, wording) - Known phishing-kit fingerprinting (favicon hash, JS obfuscation signatures) - Wallet-drainer family classification (Angel, MS, Rainbow, Pink, Inferno, ...) - Free-TLS vs paid-cert ratio (throwaway infrastructure signal) - Registrar/hosting abuse history (this registrar's track record) - Human researcher sign-off (operator takedown team) A domain present in our database is ALREADY flagged. A low VT count by itself does NOT mean the domain is safe — new scam domains routinely show 0/95 VT for their first 7–30 days while actively draining wallets. Always cross-reference the composite score and the individual indicators above, not just VT. ## CORRECTIONS / APPEALS ---------------------------------------------------------------- Full HTML report: https://phishdestroy.io/domain/address-track.com/ JSON API: https://api.destroy.tools/v1/check?domain=address-track.com Appeal a flag: https://phishdestroy.io/appeals/ (responded to within 48 hours, FP rate <0.01%) Submit a report: https://t.me/PhishDestroy_bot About PhishDestroy: independent open-source threat-intelligence platform. Tracked: 189,469 domains (59,780 alive under monitoring, 128,126 confirmed takedowns/dead). Site: https://phishdestroy.io