# PhishDestroy threat dossier — amlproof.online ================================================================ Fetched: 2026-06-30 05:26:16 UTC Canonical: https://phishdestroy.io/domain/amlproof.online/ ## VERDICT ---------------------------------------------------------------- TAKEN DOWN (neutralised) Composite threat score: 100/100 (PhishDestroy scoring — see methodology below) Scam classification: AML Scam Phishing kit: Verification Scam ## DETECTION EVIDENCE ---------------------------------------------------------------- VirusTotal: 2/91 security vendors flagged this domain Flagging vendors: ESET, LevelBlue URLQuery: 3 detections Public blocklists: listed on 1 independent blocklist ## INFRASTRUCTURE ---------------------------------------------------------------- IP address: 87.120.219.250 (GB, London) ASN: AS215540 GLOBAL CONNECTIVITY SOLUTIONS LLP Hosting org: AS215540 GLOBAL CONNECTIVITY SOLUTIONS LLP Registrar: Global Domain Group LLC Nameservers: ["andronicus.ns.cloudflare.com", "imani.ns.cloudflare.com"] Page title: Crypto Wallet Verification ## TLS CERTIFICATE ---------------------------------------------------------------- Issuer: Let's Encrypt / YR1 Expires: 2026-09-22 Status: INVALID chain Fingerprint: f7a386dcc96a052c88614b3444de2026f1edad6d36301eafed2f723c4bd6fbf3 Subject Alternative Names (related infrastructure — often same operator): - www.amlproof.online ## ABUSE-REPORT HISTORY (evidence of registrar non-response) ---------------------------------------------------------------- Status: CLOSED — no report required. This domain was neutralised before the abuse-report cycle could be dispatched — either the hosting provider / registrar suspended it on their own, the DNS went dead, or the operator abandoned the infrastructure. PhishDestroy keeps the evidence bundle on file for audit but no formal notice was sent. ## TIMELINE ---------------------------------------------------------------- First detected: 2026-06-29 03:32:37 UTC (by PhishDestroy tracker) First reported: 2026-06-29 01:34:41 UTC (abuse notice filed) Last verified: 2026-06-30 07:15:28 UTC Neutralised: 2026-06-29 12:16:25 UTC Current status: taken down (registrar suspended or DNS dead) ## EXTERNAL CORROBORATION (third-party evidence) ---------------------------------------------------------------- URLScan.io: https://urlscan.io/result/019f1101-0deb-76b9-aa82-d8ff67130a9a/ URLQuery: https://urlquery.net/report/28085120-946e-4a87-b44f-3417ef198e7b Wayback Machine: https://web.archive.org/web/*/amlproof.online crt.sh CT logs: https://crt.sh/?q=%25.amlproof.online Google transparency: https://transparencyreport.google.com/safe-browsing/search?url=amlproof.online AlienVault OTX: https://otx.alienvault.com/indicator/domain/amlproof.online URLhaus: https://urlhaus.abuse.ch/host/amlproof.online/ ## ANALYST NARRATIVE ---------------------------------------------------------------- [Generated: 2026-06-29 03:34:54 UTC — narrative may predate facts above. Treat fields in TIMELINE / DETECTION EVIDENCE / INFRASTRUCTURE as authoritative if they differ from the prose below.] This domain is flagged as an active crypto drainer phishing operation, designed to steal cryptocurrency wallet credentials and drain funds from victims. Analysis indicates the site employs wallet verification impersonation, a tactic commonly associated with malicious smart contract interactions that trigger unauthorized transactions. The specific threat type—crypto drainer—poses a high financial risk to users who connect their wallets or input seed phrases, as funds may be irreversibly transferred to attacker-controlled addresses. Infrastructure analysis reveals the following technical indicators: the domain amlproof.online resolves to IP address 87.120.219.250, which currently hosts the active phishing page titled 'Crypto Wallet Verification.' VirusTotal reports zero detections out of 95 security engines, suggesting the campaign remains undetected by most automated systems. The SSL certificate is issued by Let's Encrypt, a common choice for both legitimate and malicious sites, providing no inherent trust signal. No blocklist entries or reputation-based trust scores were identified at the time of assessment, though the domain's recent creation and lack of historical footprint align with typical phishing lifecycle patterns. Mitigation steps specific to crypto drainer threats include immediate wallet disconnection from any suspicious sites, revocation of active smart contract approvals via blockchain explorers, and verification of transaction histories for unauthorized transfers. Users should avoid interacting with unverified wallet verification prompts, particularly those mimicking legitimate services. Security teams are advised to monitor for connections to 87.120.219.250 and the domain amlproof.online in network logs, and to update endpoint detection rules to flag wallet-related phishing attempts. Given the financial risk, affected users should transfer remaining funds to a new wallet address and report the incident to relevant blockchain security platforms for further analysis and potential fund recovery efforts. [Updates since narrative was generated:] - Public blocklists: now listed on 1 feed ## EVIDENCE HASHES ---------------------------------------------------------------- PhishDestroy Case ID: PD-20260629-80779F Favicon MD5: b8a0bf372c762e966cc99ede8682bc71 TLS cert SHA-256: f7a386dcc96a052c88614b3444de2026f1edad6d36301eafed2f723c4bd6fbf3 ## SCORING METHODOLOGY ---------------------------------------------------------------- Composite score is NOT derived from VirusTotal alone. PhishDestroy aggregates: - VirusTotal positive ratio - Public blocklist consensus (MetaMask, ScamSniffer, OpenPhish, PhishTank, URLhaus, CryptoFirewall, SEAL, Polkadot, Enkrypt, Phishunt, DiscordPhishing, PhishingDB) - Cloaking detection (HTTP 666 or rendering delta between bot and real visitor) - DNS-filter consensus (Quad9, CleanBrowsing, NextDNS, AdGuard, Cloudflare, etc.) - AlienVault OTX pulses + Cloudflare Radar + Google Safe Browsing - URLScan / URLQuery verdicts - Brand-impersonation heuristics (DOM analysis of forms, logos, wording) - Known phishing-kit fingerprinting (favicon hash, JS obfuscation signatures) - Wallet-drainer family classification (Angel, MS, Rainbow, Pink, Inferno, ...) - Free-TLS vs paid-cert ratio (throwaway infrastructure signal) - Registrar/hosting abuse history (this registrar's track record) - Human researcher sign-off (volunteer takedown team) A domain present in our database is ALREADY flagged. A low VT count by itself does NOT mean the domain is safe — new scam domains routinely show 0/95 VT for their first 7–30 days while actively draining wallets. Always cross-reference the composite score and the individual indicators above, not just VT. ## CORRECTIONS / APPEALS ---------------------------------------------------------------- Full HTML report: https://phishdestroy.io/domain/amlproof.online/ JSON API: https://api.destroy.tools/v1/check?domain=amlproof.online Appeal a flag: https://phishdestroy.io/appeals/ (responded to within 48 hours, FP rate <0.01%) Submit a report: https://t.me/PhishDestroy_bot About PhishDestroy: volunteer-driven open-source threat-intelligence platform. Tracked: 172,677 domains (13,093 alive under monitoring, 158,994 confirmed takedowns/dead). Site: https://phishdestroy.io