Skip to security report
⚠️
This domain has been flagged as malicious
Security engines reporting a detection: 4. Public blocklists reporting a match: 3. Exercise extreme caution — do not enter credentials or personal information.
Domain security and threat intelligence

cryptoaml-check[.]online

“AML Check”

Threat verdict Critical 95/100 evidence score
Availability Content unavailable Content was unavailable in the latest observation
VirusTotal detections: 4/93 Stored blocklist matches: 3 URLQuery threat systems: 1 alert Brand impersonation: Csgo
Jan 27, 2026 Csgo 1 Report Sent

Evidence Summary

CRITICAL
Evidence score
95/100

The website cryptoaml-check.online was configured to impersonate the csgo brand under the page title "AML Check". It is classified as a cryptocurrency scam. The primary threat is that it likely attempted to trick visitors into providing sensitive information or funds under the pretense of an anti-money laundering verification service for csgo-related transactions.

Technical analysis reveals the domain was created on 2026-02-21 and is registered with Beget LLC. It resolves to IP address 45.130.41.69, which is hosted in Russia (RU) on AS198610 Beget LLC. VirusTotal flagged it with 4 out of 95 detections. Specific blocklists from alphaMountain.ai, Forcepoint ThreatSeeker, Gridinsoft, and SOCRadar identified the site. The domain has no SSL certificate. Its nameservers are ns1.beget.com, ns1.beget.pro, ns2.beget.com, and ns2.beget.pro.

The site is currently offline. The risk level is significant, as indicated by a GridinSoft trust score of 0 out of 100 and a ScamAdviser trust score of 49 out of 100. The overall domain risk score is 10.

Submitted Evidence Snapshot

Sent
Ledger records
1
Case ID
PD-20260127-34F141
Captured page title
AML Check
PDF artifact
PDF evidence
Full evidence text
Policy Violations:
Acceptable Use Policy (AUP): The domain cryptoaml-check.online is engaged in phishing activities, which constitutes a clear violation of your AUP prohibiting illegal activities, fraud, and deception.
Terms of Service (TOS): The activities associated with this domain violate your TOS, which reserves the right to suspend or terminate services for any illegal or fraudulent activities.
Applicable Laws (Unknown):
Computer Fraud and Abuse Act (CFAA): This U.S. federal law prohibits unauthorized access to computers and networks, making phishing activities a violation.
Wire Fraud Statute (18 U.S.C. § 1343): This statute criminalizes schemes to defraud individuals or entities via electronic communications, which applies to phishing schemes.
Anti-Phishing Consumer Protection Act: This law aims to combat phishing by imposing penalties on those who engage in deceptive practices to obtain sensitive information.
Regulatory Note: Failure to take immediate action against this domain may expose your organization to legal liability and regulatory scrutiny. Compliance with your AUP and TOS is essential to mitigate risks associated with hosting fraudulent activities.
VirusTotal
VirusTotal
4 det.
URLQuery
URLQuery
1 threat alert
Observed status
Content unavailable HTTP 502
PhishDestroy
DestroyList
Listed
Reports Sent
1

Data Coverage

VirusTotal 4 / 93 URLQuery 1 threat-system alert PhishStats not checked OTX no community references CF Radar scan completed URLScan capture stored report URLScan verdict malicious DNS blocks not checked TLS no certificate data WHOIS not parsed Screenshot 3 captures · 3 sources Redirect chain not probed
Security Signals
SA Scamadviser Warnings
The website's owner is hiding his identity on WHOIS using a paid service This website does not have many visitors We found many low rated websites on the same server This website has only been registered recently.
According to the SSL check the certificate is valid DNSFilter considers this website safe
Network Security Intelligence
Threat Detection Systems 1 alert
Detection System Indicator Verdict Alert
DNS4EU cryptoaml-check.online malicious Sinkholed

Threat Response Pipeline

Discovery
Checks
Reports
Availability
14/14

Blocklist coverage

10 monitored external feeds · stored snapshot Aug 12, 2026

7 monitored external feeds No match

Detection timeline

  1. Cloudflare Radar

    Cloudflare Radar scan stored · Open scan

Stored Capture

Page Title
AML Check
Impersonates
Csgo Facebook Instagram LinkedIn Telegram TikTok YouTube

Domain Intelligence

Domain
URLScan Verdict Malicious score 100 Phishing report ↗
Server / ASN nginx-reuseport/1.21.1 · AS198610 Beget LLC
IP Reputation IP abuse confidence 0/100 0 reports checked Jun 16, 2026
Registrar Beget RU(RU)
IP Address 45.130.41.69 RU
GeoRU Saint Petersburg, RU
NetworkAS198610 · Beget LLC
HTTP Status502 Error
Time to First Unavailability 86 days
What we count Elapsed time from the first stored abuse report to the first observation that the content was unavailable. This does not establish the cause.
What each report contains Stored outgoing-report records may reference evidence available at the time, such as vendor verdicts, registration data, hosting details, classifications, or screenshots. This page does not infer the exact payload delivered, receipt, acknowledgement, or action by a recipient.
Technical detailsDNS, TLS names and timestamps
First DetectedJan 27, 2026
DOM Analysisanalyzed Mar 24, 2026DOM analysis score 10/1007 brand signals
Submitted URLhttp://cryptoaml-check.online/
Nameserversns1.beget.comns1.beget.prons2.beget.comns2.beget.pro
TLS observationscanned May 26, 2026
ICANN OVERSIGHT

Accreditation and RAA context

Registrar accreditation and DNS abuse obligations

For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.

Accreditation is a contract, not a safety certification.

RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.

Accountability draft Nothing is sent automatically.

Forensic Intelligence

External Scripts 1
https://performance.radar.cloudflare.com/beacon.js
Report This Domain Submit evidence & help protect others

VirusTotal Analysis

4 / 93 security vendors flagged this domain
View on VT
Last analyzed
alphaMountain.ai
Forcepoint ThreatSeeker
Gridinsoft
SOCRadar

Were You Affected by This Site?

If credentials were compromised, report immediately. Do not engage with recovery scammers.

If credentials, payment data, or files were exposed, report the incident immediately. Change affected passwords, revoke active sessions, and scan the device.

Europol
Find the official reporting channel for your EU country
National police directory
Beware of recovery scammers! Recovery scammers may pose as investigators, lawyers, or tracing services. Do not pay upfront fees or disclose credentials. Learn more about recovery fraud →

Report to Your Local Authorities

Select your country to get official cybercrime contacts, or create a complaint draft →.

97-country directory
Template-based draft • optional AI wording assistance requires separate consent Review and submit it yourself

Check Any Domain

Threat analysis using stored blocklist, WHOIS, DNS, and public scan evidence

Scan Now

Report Phishing

Submit suspicious domains to our threat database — protect the community

Report

Live Threat Feed

Recent phishing reports and observed availability changes

Monitor

Stay Informed, Stay Safe

Monitor live threats or contest this listing if you believe it's a false positive

Live Threat Feed Appeal This Listing

External tools

ScamAdviserScamAdviser Trust score 49/100Status: Caution RecommendedOpen source
HTML · IFRAME

Embed This Report

Share this threat intelligence on your website or blog

embed.html
<iframe
  src="https://phishdestroy.io/embed/domain/cryptoaml-check.online"
  title="PhishDestroy threat report for cryptoaml-check.online"
  width="100%" height="320"
  loading="lazy"
  referrerpolicy="no-referrer"
  sandbox="allow-same-origin allow-popups allow-popups-to-escape-sandbox"
  style="border:0;border-radius:12px;max-width:100%"
></iframe>

A Very Sincere Thank-You Note

Satirical draft generator

Recipient
Fee context

Satirical draft. Fee figures are estimates; exact attribution to this domain is not claimed.