# PhishDestroy threat dossier — aml-compliance.org ================================================================ Fetched: 2026-07-26 11:12:24 UTC Canonical: https://phishdestroy.io/domain/aml-compliance.org/ ## VERDICT ---------------------------------------------------------------- CRITICAL THREAT — DO NOT VISIT Composite threat score: 100/100 (PhishDestroy scoring — see methodology below) Scam classification: AML Scam Targeted brand: AML Scam Phishing kit: Giveaway Scam ## DETECTION EVIDENCE ---------------------------------------------------------------- VirusTotal: 9/91 security vendors flagged this domain Flagging vendors: BitDefender, CyRadar, Forcepoint ThreatSeeker, Fortinet, G-Data, Gridinsoft, Kaspersky, SOCRadar, Sophos Public blocklists: listed on 3 independent blocklists ## INFRASTRUCTURE ---------------------------------------------------------------- IP address: 186.2.175.35 (RU, Moscow) ASN: ASAS59692 IQWEB IQWeb FZ-LLC, AE Hosting org: AS59692 IQWeb FZ-LLC Registrar: Fewmoretaps OU d/b/a Trustname.com !!! REGISTRAR INTEGRITY ALERT — Trustname / Fewmoretaps OU !!! Trustname (IANA #4318) is a shell company declaring EUR 120 annual revenue, 1 employee, negative equity, Belarusian ownership. Explicitly advertises itself as 'bulletproof' in its DNS TXT records. Primary source: https://phishdestroy.io/trustname-bulletproof-exposed Nameservers: ares.trustname.com, ns1.anycastdns.cz, ns2.anycastdns.cz, zeus.trustname.com Registered: 2026-06-22 Expires: 2027-06-22 Page title: AML-Compliance.org — Free Crypto Wallet AML Check | Multi-Chain Risk Screening HTTP response: 200 ## TLS CERTIFICATE ---------------------------------------------------------------- Issuer: Let's Encrypt / YR2 Expires: 2026-09-27 Status: INVALID chain Fingerprint: 4a3dbabc63ba2db5a316313b0e5a861d9d9f709c458933a2c7d7367ea8554bdc ## ABUSE-REPORT HISTORY (evidence of registrar non-response) ---------------------------------------------------------------- Status: pending notification queue. No abuse reports filed yet — this domain is waiting for the next cycle of our automated abuse-reporter. ## TIMELINE ---------------------------------------------------------------- Domain registered: 2026-06-22 (per WHOIS / CT — may reflect a renewal or transfer date, not first-ever registration) First detected: 2026-07-23 11:59:10 UTC (by PhishDestroy tracker) First reported: 2026-07-23 10:00:36 UTC (abuse notice filed) Last verified: 2026-07-26 12:27:11 UTC Current status: ACTIVE / observable ## EXTERNAL CORROBORATION (third-party evidence) ---------------------------------------------------------------- URLScan.io: https://urlscan.io/result/019f8e69-4fa9-7011-bfc3-78a59e459a85/ URLQuery: https://urlquery.net/report/db24f0ce-33e6-4742-91c4-42c77e66b822 Wayback Machine: https://web.archive.org/web/*/aml-compliance.org crt.sh CT logs: https://crt.sh/?q=%25.aml-compliance.org Google transparency: https://transparencyreport.google.com/safe-browsing/search?url=aml-compliance.org AlienVault OTX: https://otx.alienvault.com/indicator/domain/aml-compliance.org URLhaus: https://urlhaus.abuse.ch/host/aml-compliance.org/ ## ANALYST NARRATIVE ---------------------------------------------------------------- [Generated: 2026-07-23 11:59:31 UTC — narrative may predate facts above. Treat fields in TIMELINE / DETECTION EVIDENCE / INFRASTRUCTURE as authoritative if they differ from the prose below.] aml-compliance.org Safety Check — AML Phishing Detected Analysis of aml-compliance.org indicates a recently registered domain exhibiting characteristics consistent with anti-money laundering (AML) themed phishing activity. The domain was created on June 22, 2026, and remains active as of July 23, 2026. It is registered through Fewmoretaps OU, operating under the Trustname.com brand, with nameservers pointing to ares.trustname.com, ns1.anycastdns.cz, ns2.anycastdns.cz, and zeus.trustname.com, suggesting reliance on a shared or reseller DNS infrastructure. The domain resolves to the IP address 186.2.175.35, though no hosting provider or autonomous system details are currently available for further attribution. At the time of assessment, the domain appears on one security blocklist, while VirusTotal scans from 91 vendors report no detections, though this absence does not confirm legitimacy. No HTTP status, SSL certificate details, or page title data are available to clarify the exact content or targeting methodology. Infrastructure analysis reveals no confirmed links to known phishing kits or brand impersonation, though the domain name itself aligns with common AML compliance lures used in credential harvesting or fraudulent document collection schemes. Defenders are advised to monitor for inbound links or emails referencing aml-compliance.org, particularly those targeting financial institutions, regulatory compliance teams, or employees handling sensitive customer data. Blocking or flagging the domain at the DNS or proxy level is recommended pending further analysis. Additional scrutiny of the associated IP and registrar infrastructure may reveal related malicious domains. ## EVIDENCE HASHES ---------------------------------------------------------------- PhishDestroy Case ID: PD-20260723-660F9C TLS cert SHA-256: 4a3dbabc63ba2db5a316313b0e5a861d9d9f709c458933a2c7d7367ea8554bdc ## SCORING METHODOLOGY ---------------------------------------------------------------- Composite score is NOT derived from VirusTotal alone. PhishDestroy aggregates: - VirusTotal positive ratio - Public blocklist consensus (MetaMask, ScamSniffer, OpenPhish, PhishTank, URLhaus, CryptoFirewall, SEAL, Polkadot, Enkrypt, Phishunt, DiscordPhishing, PhishingDB) - Cloaking detection (HTTP 666 or rendering delta between bot and real visitor) - DNS-filter consensus (Quad9, CleanBrowsing, NextDNS, AdGuard, Cloudflare, etc.) - AlienVault OTX pulses + Cloudflare Radar + Google Safe Browsing - URLScan / URLQuery verdicts - Brand-impersonation heuristics (DOM analysis of forms, logos, wording) - Known phishing-kit fingerprinting (favicon hash, JS obfuscation signatures) - Wallet-drainer family classification (Angel, MS, Rainbow, Pink, Inferno, ...) - Free-TLS vs paid-cert ratio (throwaway infrastructure signal) - Registrar/hosting abuse history (this registrar's track record) - Human researcher sign-off (operator takedown team) A domain present in our database is ALREADY flagged. A low VT count by itself does NOT mean the domain is safe — new scam domains routinely show 0/95 VT for their first 7–30 days while actively draining wallets. Always cross-reference the composite score and the individual indicators above, not just VT. ## CORRECTIONS / APPEALS ---------------------------------------------------------------- Full HTML report: https://phishdestroy.io/domain/aml-compliance.org/ JSON API: https://api.destroy.tools/v1/check?domain=aml-compliance.org Appeal a flag: https://phishdestroy.io/appeals/ (responded to within 48 hours, FP rate <0.01%) Submit a report: https://t.me/PhishDestroy_bot About PhishDestroy: independent open-source threat-intelligence platform. Tracked: 196,805 domains (66,124 alive under monitoring, 129,132 confirmed takedowns/dead). Site: https://phishdestroy.io