# amlview.net — SUSPICIOUS > amlview.net is a recently registered domain (March 21, 2026) actively hosting a generic phishing campaign. Resolves to 188.114.97. ## Summary amlview.net has been flagged for active credential harvesting operations, posing an immediate risk to users who may interact with its phishing content. The domain is currently under investigation but remains accessible, with no detections recorded across 95 VirusTotal engines as of the latest scan. This suggests the threat is either newly emerged or evading traditional signature-based detection mechanisms. amlview.net was registered through PDR Ltd. d/b/a PublicDomainRegistry.com on March 21, 2026, and resolves to IP address 188.114.97.3. The domain utilizes a Let's Encrypt SSL certificate, which may lend an air of legitimacy to potential victims. Despite its recent creation, the domain has not yet been flagged by major blocklists or threat intelligence platforms, and no detections have been recorded on VirusTotal (0/95). This combination of factors—fresh registration, clean reputation, and active hosting—creates a high-risk scenario for unsuspecting users. To mitigate exposure to this threat, users should avoid accessing amlview.net or any subdomains associated with it. Organizations are advised to implement network-level blocking for the IP address 188.114.97.3 and monitor for any outbound connections to this domain. Additionally, users who may have already interacted with this domain should change any credentials that could have been compromised and enable multi-factor authentication where possible. Security teams should also consider monitoring for related infrastructure, as threat actors often reuse similar registration patterns or hosting providers for subsequent campaigns. Early detection and containment are critical to preventing widespread credential theft. ## Threat Details - Verdict: SUSPICIOUS - Site status: unknown (HTTP ?) ## Domain Intelligence - Registered: 2026-03-21 13:38:45 - Registrar: PDR Ltd. d/b/a PublicDomainRegistry.com - IP: 188.114.97.3 ## Detection Status - VirusTotal: 0 vendors flagged - Google Safe Browsing: clean - Blocklists: 0 hits ## Evidence - Cloudflare Radar: https://radar.cloudflare.com/scan/df3e06d0-97a4-4d83-9ad8-af366924f647 - PhishDestroy: https://phishdestroy.io/domain/amlview.net/ - LLM endpoint: https://phishdestroy.io/domain/amlview.net/llm.txt ## If You Visited This Site 1. Change any passwords you may have entered 2. Enable 2FA on all related accounts 3. Monitor your accounts for unauthorized activity 4. Report to: FBI IC3, Europol, local authorities --- Report by PhishDestroy | https://phishdestroy.io/domain/amlview.net/ Last updated: 2026-03-22