# PhishDestroy threat dossier — amlbot-scan.com ================================================================ Fetched: 2026-05-09 20:20:57 UTC Canonical: https://phishdestroy.io/domain/amlbot-scan.com/ ## VERDICT ---------------------------------------------------------------- HIGH THREAT — malicious activity confirmed Composite threat score: 62/100 (PhishDestroy scoring — see methodology below) Scam classification: AML Scam Targeted brand: AMLBot ## DETECTION EVIDENCE ---------------------------------------------------------------- VirusTotal: 5/95 security vendors flagged this domain Flagging vendors: ADMINUSLabs, alphaMountain.ai, CRDF, Forcepoint ThreatSeeker, Fortinet URLQuery: 2 detections ## INFRASTRUCTURE ---------------------------------------------------------------- IP address: 104.21.90.220 (CA, Toronto) ASN: AS13335 Cloudflare, Inc. Hosting org: Cloudflare, Inc. Registrar: Dynadot Inc Nameservers: edna.ns.cloudflare.com, leo.ns.cloudflare.com Registered: 2026-02-25 Page title: AMLBot - Comprehensive AML Compliance Solutions for Crypto HTTP response: 200 ## TLS CERTIFICATE ---------------------------------------------------------------- Issuer: Let's Encrypt / E7 Expires: 2026-07-24 Status: INVALID chain Fingerprint: 3bec494e72c6c46d6cbea4f198db518c9c139f9714a497deffcb966a1f54afb3 ## ABUSE-REPORT HISTORY (evidence of registrar non-response) ---------------------------------------------------------------- Status: pending notification queue. No abuse reports filed yet — this domain is waiting for the next cycle of our automated abuse-reporter. ## TIMELINE ---------------------------------------------------------------- Domain registered: 2026-02-25 (per WHOIS / CT — may reflect a renewal or transfer date, not first-ever registration) First detected: 2026-05-09 20:35:31 UTC (by PhishDestroy tracker) First reported: 2026-05-09 17:36:26 UTC (abuse notice filed) Last verified: 2026-05-09 22:00:06 UTC Current status: ACTIVE / observable ## EXTERNAL CORROBORATION (third-party evidence) ---------------------------------------------------------------- URLScan.io: https://urlscan.io/result/019e0dcd-249a-712b-8797-902c57776857/ URLQuery: https://urlquery.net/report/7f40b148-9486-4319-a9a5-42e93cf9a7a9 Wayback Machine: https://web.archive.org/web/*/amlbot-scan.com crt.sh CT logs: https://crt.sh/?q=%25.amlbot-scan.com Google transparency: https://transparencyreport.google.com/safe-browsing/search?url=amlbot-scan.com AlienVault OTX: https://otx.alienvault.com/indicator/domain/amlbot-scan.com URLhaus: https://urlhaus.abuse.ch/host/amlbot-scan.com/ ## ANALYST NARRATIVE ---------------------------------------------------------------- [Generated: 2026-05-09 20:36:10 UTC — narrative may predate facts above. Treat fields in TIMELINE / DETECTION EVIDENCE / INFRASTRUCTURE as authoritative if they differ from the prose below.] PhishDestroy identifies amlbot-scan.com as an active credential theft phishing domain impersonating legitimate security scan services to harvest user credentials. The domain leverages a generic but deceptive naming convention (amlbot-scan) to imply association with automated malware scanning bots, while its fraudulent login interfaces are designed to trick victims into surrendering account credentials. No evidence suggests the use of a specific drainer kit or brand impersonation at this stage; however, the site’s structure and SSL certificate (Let's Encrypt) indicate a semi-professional operation likely intended to facilitate immediate credential harvesting. amlbot-scan.com exhibits multiple suspicious technical indicators. According to VirusTotal, only 5 out of 95 security vendors have flagged the domain as malicious as of the most recent analysis. This low detection rate may reflect the domain's recency or evolving tactics. The domain was registered through Dynadot Inc on February 25, 2026, and currently resolves to IP address 104.21.90.220. While Google Safe Browsing (GSB) status remains unverified in this dataset, the presence of a valid Let's Encrypt SSL certificate suggests an attempt to establish trustworthiness. Additionally, the domain’s age and low blocklist count imply it has not yet been widely categorized across threat intelligence platforms. As of the latest assessment, amlbot-scan.com remains active and poses an elevated risk to users who may encounter it through phishing campaigns or misleading redirects. Immediate mitigation actions include blocking the domain at the network and DNS levels, updating firewall rules to restrict outbound connections to 104.21.90.220, and flagging the domain for takedown through the registrar (Dynadot Inc). Users are strongly advised to avoid accessing the site and to verify the legitimacy of any unexpected security scan prompts via official channels. Remaining risk stems from the domain’s recent creation and low initial detection rate, which may allow it to evade some security controls temporarily. ## EVIDENCE HASHES ---------------------------------------------------------------- PhishDestroy Case ID: PD-20260509-07FCBA Favicon MD5: a2bd7298aea9971e039fc01c3a944f0d TLS cert SHA-256: 3bec494e72c6c46d6cbea4f198db518c9c139f9714a497deffcb966a1f54afb3 ## SCORING METHODOLOGY ---------------------------------------------------------------- Composite score is NOT derived from VirusTotal alone. PhishDestroy aggregates: - VirusTotal positive ratio - Public blocklist consensus (MetaMask, ScamSniffer, OpenPhish, PhishTank, URLhaus, CryptoFirewall, SEAL, Polkadot, Enkrypt, Phishunt, DiscordPhishing, PhishingDB) - Cloaking detection (HTTP 666 or rendering delta between bot and real visitor) - DNS-filter consensus (Quad9, CleanBrowsing, NextDNS, AdGuard, Cloudflare, etc.) - AlienVault OTX pulses + Cloudflare Radar + Google Safe Browsing - URLScan / URLQuery verdicts - Brand-impersonation heuristics (DOM analysis of forms, logos, wording) - Known phishing-kit fingerprinting (favicon hash, JS obfuscation signatures) - Wallet-drainer family classification (Angel, MS, Rainbow, Pink, Inferno, ...) - Free-TLS vs paid-cert ratio (throwaway infrastructure signal) - Registrar/hosting abuse history (this registrar's track record) - Human researcher sign-off (volunteer takedown team) A domain present in our database is ALREADY flagged. A low VT count by itself does NOT mean the domain is safe — new scam domains routinely show 0/95 VT for their first 7–30 days while actively draining wallets. Always cross-reference the composite score and the individual indicators above, not just VT. ## CORRECTIONS / APPEALS ---------------------------------------------------------------- Full HTML report: https://phishdestroy.io/domain/amlbot-scan.com/ JSON API: https://api.destroy.tools/v1/check?domain=amlbot-scan.com Appeal a flag: https://phishdestroy.io/appeals/ (responded to within 48 hours, FP rate <0.01%) Submit a report: https://t.me/PhishDestroy_bot About PhishDestroy: volunteer-driven open-source threat-intelligence platform. Tracked: 147,737 domains (47,270 alive under monitoring, 100,184 confirmed takedowns/dead). Site: https://phishdestroy.io