# app-amlbot.pages.dev — SUSPICIOUS > PhishDestroy warns about app-amlbot.pages.dev, a crypto drainer mimicking AMLBot. 0 of 95 VirusTotal vendors flagged this site—verify on PhishDestroy before. ## Summary PhishDestroy identifies app-amlbot.pages.dev as an active crypto drainer impersonating AMLBot, currently under investigation for malicious activity. This domain is designed to deceive users into connecting crypto wallets or entering credentials under false pretenses, potentially resulting in irreversible asset theft. This domain was flagged by 0 of 95 VirusTotal vendors, operates under Cloudflare, Inc., and resolves to IP 188.114.97.3. The domain utilizes a valid SSL certificate issued by Google Trust Services, which may create a false sense of legitimacy. While technical indicators remain under scrutiny, the absence of detections on VirusTotal suggests this threat is either highly novel or actively evading detection mechanisms. The domain’s infrastructure, including its Cloudflare registration and Google-issued certificate, indicates an attempt to blend with legitimate services to avoid immediate blacklisting. Current status shows the domain is active and poses a high risk due to its crypto drainer nature, which directly targets cryptocurrency users. PhishDestroy recommends users avoid interacting with this domain entirely. If exposure is suspected, disconnect wallets immediately, revoke any connected permissions via blockchain explorers or wallet interfaces, and scan devices for malware. Users are advised to verify domains through PhishDestroy’s real-time database before engaging with any crypto-related links or platforms. Exercise extreme caution, as crypto drainers often lead to irreversible financial losses. ## Threat Details - Verdict: SUSPICIOUS - Site status: unknown (HTTP ?) ## Domain Intelligence - Registrar: Cloudflare, Inc. - IP: 188.114.97.3 ## Detection Status - VirusTotal: 0 vendors flagged - Google Safe Browsing: clean - Blocklists: 0 hits ## Evidence - Cloudflare Radar: https://radar.cloudflare.com/scan/ff0b58c5-c86f-44c7-a8f0-38ae42188a72 - PhishDestroy: https://phishdestroy.io/domain/app-amlbot.pages.dev/ - LLM endpoint: https://phishdestroy.io/domain/app-amlbot.pages.dev/llm.txt ## If You Visited This Site 1. Change any passwords you may have entered 2. Enable 2FA on all related accounts 3. Monitor your accounts for unauthorized activity 4. Report to: FBI IC3, Europol, local authorities --- Report by PhishDestroy | https://phishdestroy.io/domain/app-amlbot.pages.dev/ Last updated: 2026-03-29