drainer[.]nexprofits[.]com
“AMLBot”
drainer.nexprofits.com — Contenido no disponible. Tipo de estafa: Crypto Drainer. Resumen de las pruebas: VirusTotal 5/91 (ADMINUSLabs, alphaMountain.ai, Fortinet, Gridinsoft, SOCRadar); PhishDestroy score 78/100. Registrador: TuringSign.
El análisis detallado de PhishDestroy AI se mantiene en inglés para conservar el registro forense original.
The domain www.drainer.nexprofits.com is identified as a crypto drainer phishing site, specifically targeting users to steal cryptocurrency. Analysis indicates that this domain was used to deploy a malicious bot known as AMLBot, which is designed to redirect users to fraudulent cryptocurrency wallets and steal their assets.
Evidence supporting the threat analysis includes the domain being flagged by 7 out of 95 security vendors on VirusTotal, indicating a moderate level of recognition among cybersecurity professionals. The domain is registered through TuringSign Inc. d/b/a Cosmotown and was created on March 10, 2026. It has a Gridinsoft trust score of 0/100, further confirming its malicious nature. The domain has also appeared on one security blocklist and was previously blocked by PhishDestroy. Infrastructure analysis reveals the use of Tailwind CSS, LiteSpeed, jsDelivr, and HTTP/3, which are common technologies used to create and host phishing sites efficiently.
Users who have visited this domain are advised to immediately check their cryptocurrency wallets for any unauthorized transactions and change their passwords on any related platforms. It is also recommended to enable two-factor authentication (2FA) and monitor their accounts for any suspicious activity. If any financial loss is suspected, users should report the incident to their respective cryptocurrency exchanges and local law enforcement agencies.
Inteligencia de seguridad de red
Proceso de respuesta ante amenazas Pipeline
Estado de la lista de bloqueados pública
Captura guardada
Inteligencia de dominios
Detalles técnicosDNS, SAN de SSL, marcas de tiempo
ICANN OVERSIGHT
Registration: nexprofits.com
Acreditación y contexto RAA
Acreditación y contexto RAA
Registrar accreditation and DNS abuse obligations
For the registrable domain nexprofits.com behind this subdomain, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Tecnologías · 4 identified
JSDelivr is a free public CDN for open-source projects. It can serve web files directly from the npm registry and GitHub repositories without any configuration.
www.jsdelivr.com 100 % de confianzaHTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org 100 % de confianzaAnálisis de VirusTotal
Análisis del rendimiento del sitio
Google PageSpeed Insights — mobile performance audit of drainer.nexprofits.com · checked Jun 26, 2026
Datos y informes externos
¿Te ha afectado esta página web?
Si ingresó credenciales de cuenta, información personal o de pago, o descargó un archivo de este dominio, tome medidas inmediatas. A continuación encontrará recursos que le ayudarán a informar el incidente y protegerse.
Informa a las autoridades locales
Seleccione su país para obtener contactos oficiales de cibercrimen o crear un borrador de queja →.
Comprobar cualquier dominio
Análisis de amenazas utilizando listas de bloqueo almacenadas, WHOIS, DNS y evidencia de escaneo público
Escanear ahoraDenunciar un intento de phishing
Envía los dominios sospechosos a nuestra base de datos de amenazas: protege a la comunidad
DenunciarFlujo de amenazas en tiempo real
Informes de phishing recientes y cambios de disponibilidad observados
MonitorizarMantente informado, mantente a salvo
Supervisa las amenazas en tiempo real o impugna esta entrada si crees que se trata de un falso positivo.