# PhishDestroy threat dossier — amlcertify.eu ================================================================ Fetched: 2026-06-30 02:02:14 UTC Canonical: https://phishdestroy.io/domain/amlcertify.eu/ ## VERDICT ---------------------------------------------------------------- TAKEN DOWN (neutralised) Composite threat score: 56/100 (PhishDestroy scoring — see methodology below) Scam classification: AML Scam ## DETECTION EVIDENCE ---------------------------------------------------------------- VirusTotal: 1/91 security vendors flagged this domain Flagging vendors: SOCRadar Public blocklists: listed on 1 independent blocklist ## INFRASTRUCTURE ---------------------------------------------------------------- IP address: 99.83.231.61 (US, Seattle) ASN: ASAS16509 AMAZON-02 - Amazon.com, Inc., US Hosting org: AS16509 Amazon.com, Inc. Registrar: Porkbun LLC Nameservers: curitiba.ns.porkbun.com, fortaleza.ns.porkbun.com, fortaleza.ns.porkbun.com, salvador.ns.porkbun.com, curitiba.ns.porkbun.com, maceio.ns.porkbun.com, please, visit Page title: AML HTTP response: 200 ## TLS CERTIFICATE ---------------------------------------------------------------- Issuer: Let's Encrypt / YE2 Expires: 2026-08-30 Status: INVALID chain Fingerprint: d823dff0007f829d7f80b87dc3ecd9c88b6c3f407d051a21551d1cbd9562cfc8 Subject Alternative Names (related infrastructure — often same operator): - www.amlcertify.eu ## ABUSE-REPORT HISTORY (evidence of registrar non-response) ---------------------------------------------------------------- Status: CLOSED — no report required. This domain was neutralised before the abuse-report cycle could be dispatched — either the hosting provider / registrar suspended it on their own, the DNS went dead, or the operator abandoned the infrastructure. PhishDestroy keeps the evidence bundle on file for audit but no formal notice was sent. ## TIMELINE ---------------------------------------------------------------- First detected: 2026-06-29 01:17:49 UTC (by PhishDestroy tracker) Last verified: 2026-06-30 00:20:34 UTC Neutralised: 2026-06-29 06:17:57 UTC Current status: taken down (registrar suspended or DNS dead) ## EXTERNAL CORROBORATION (third-party evidence) ---------------------------------------------------------------- URLScan.io: https://urlscan.io/result/019f1085-8abf-71c4-be0f-390a0bbebcaa/ Wayback Machine: https://web.archive.org/web/*/amlcertify.eu crt.sh CT logs: https://crt.sh/?q=%25.amlcertify.eu Google transparency: https://transparencyreport.google.com/safe-browsing/search?url=amlcertify.eu AlienVault OTX: https://otx.alienvault.com/indicator/domain/amlcertify.eu URLhaus: https://urlhaus.abuse.ch/host/amlcertify.eu/ ## ANALYST NARRATIVE ---------------------------------------------------------------- [Generated: 2026-06-29 01:25:42 UTC — narrative may predate facts above. Treat fields in TIMELINE / DETECTION EVIDENCE / INFRASTRUCTURE as authoritative if they differ from the prose below.] This domain is flagged as an active credential theft operation targeting users in the anti-money laundering (AML) compliance sector. Analysis indicates the infrastructure is designed to impersonate legitimate AML certification platforms, likely harvesting login credentials, corporate IDs, or financial access tokens from professionals in regulated industries. The threat type is classified as credential theft, not generic phishing, due to its sector-specific targeting and the high-value data at risk. Infrastructure analysis reveals the following technical indicators: the domain resolves to IP address 75.2.60.5, registered through Porkbun LLC, and is secured with a Let’s Encrypt SSL certificate. VirusTotal reports 0 out of 95 security vendors flagging the domain, suggesting it has not yet been widely detected or blocked. No known blocklists or threat intelligence feeds currently list this domain, and no historical abuse reports are associated with the IP or registrar. The domain’s creation date and registration details remain unremarkable, providing no immediate red flags beyond its behavioral indicators. Mitigation steps for organizations and individuals include immediate domain blocking at the network level, particularly for entities in financial compliance, legal, or regulatory sectors. Users should verify the legitimacy of any AML-related communications by cross-referencing with known official platforms and avoiding direct interaction with unsolicited links. Security teams are advised to monitor for anomalous login attempts or unauthorized access originating from this domain, as credential theft often precedes lateral movement or fraudulent transactions. Proactive measures such as multi-factor authentication and phishing-resistant authentication protocols should be enforced for all AML-related accounts. ## EVIDENCE HASHES ---------------------------------------------------------------- Favicon MD5: b8a0bf372c762e966cc99ede8682bc71 TLS cert SHA-256: d823dff0007f829d7f80b87dc3ecd9c88b6c3f407d051a21551d1cbd9562cfc8 ## SCORING METHODOLOGY ---------------------------------------------------------------- Composite score is NOT derived from VirusTotal alone. PhishDestroy aggregates: - VirusTotal positive ratio - Public blocklist consensus (MetaMask, ScamSniffer, OpenPhish, PhishTank, URLhaus, CryptoFirewall, SEAL, Polkadot, Enkrypt, Phishunt, DiscordPhishing, PhishingDB) - Cloaking detection (HTTP 666 or rendering delta between bot and real visitor) - DNS-filter consensus (Quad9, CleanBrowsing, NextDNS, AdGuard, Cloudflare, etc.) - AlienVault OTX pulses + Cloudflare Radar + Google Safe Browsing - URLScan / URLQuery verdicts - Brand-impersonation heuristics (DOM analysis of forms, logos, wording) - Known phishing-kit fingerprinting (favicon hash, JS obfuscation signatures) - Wallet-drainer family classification (Angel, MS, Rainbow, Pink, Inferno, ...) - Free-TLS vs paid-cert ratio (throwaway infrastructure signal) - Registrar/hosting abuse history (this registrar's track record) - Human researcher sign-off (volunteer takedown team) A domain present in our database is ALREADY flagged. A low VT count by itself does NOT mean the domain is safe — new scam domains routinely show 0/95 VT for their first 7–30 days while actively draining wallets. Always cross-reference the composite score and the individual indicators above, not just VT. ## CORRECTIONS / APPEALS ---------------------------------------------------------------- Full HTML report: https://phishdestroy.io/domain/amlcertify.eu/ JSON API: https://api.destroy.tools/v1/check?domain=amlcertify.eu Appeal a flag: https://phishdestroy.io/appeals/ (responded to within 48 hours, FP rate <0.01%) Submit a report: https://t.me/PhishDestroy_bot About PhishDestroy: volunteer-driven open-source threat-intelligence platform. Tracked: 172,677 domains (13,021 alive under monitoring, 159,066 confirmed takedowns/dead). Site: https://phishdestroy.io