सुरक्षा रिपोर्ट पर जाएँ
Checked 09/08/2026 Ref CD92C1C1

MALICIOUS — CRITICAL

aml-bot.net की फ़िशिंग और सुरक्षा जाँच

aml-bot[.]net

PhishDestroy has identified aml-bot.net as a live crypto drainer phishing domain under active investigation.

87/100 evidence score · Critical
VirusTotal
0/94
Blocklists
4 · MetaMask, ScamSniffer
उपलब्धता
सामग्री अनुपलब्ध · HTTP 502
Report / Add Evidence Appeal this listing
2026-03-30 06:50 UTCसामग्री अनुपलब्ध · HTTP 502

Do not enter credentials, seed phrases, payment details, or personal information on this domain.

⚠️
इस डोमेन को दुर्भावनापूर्ण के रूप में चिह्नित किया गया है।
किसी मैच की रिपोर्ट करने वाली सार्वजनिक ब्लॉक सूचियाँ: 4। अत्यधिक सावधानी बरतें - क्रेडेंशियल या व्यक्तिगत जानकारी दर्ज न करें।
Jump to section
रिपोर्ट सारांश

aml-bot.net — सामग्री अनुपलब्ध (HTTP 502). ब्रांड प्रतिरूपण: Foundation; घोटाले का प्रकार: Aml Scam. साक्ष्य सारांश: VirusTotal 0/94; URLQuery 1 det.; Spamhaus DBL_PHISH; 4 external blocklist matches; PhishDestroy score 87/100. रजिस्ट्रार: NiceNIC.

मूल फॉरेंसिक रिकॉर्ड सुरक्षित रखने के लिए नीचे का विस्तृत PhishDestroy AI विश्लेषण अंग्रेज़ी में रखा गया है।

Evidence Analysis

Ref CD92C1C1

PhishDestroy has identified aml-bot.net as a live crypto drainer phishing domain under active investigation. This domain purports to offer automated anti-money laundering (AML) compliance bots for cryptocurrency users, but all indicators suggest malicious intent to drain victim wallets upon connection.

This domain was flagged by security researchers and is currently blocked by two reputable blocklists including ScamSniffer and Enkrypt. VirusTotal analysis shows 0 out of 95 security engines currently detecting the payload, indicating a low initial detection rate despite clear malicious indicators. The domain was registered on March 29, 2026 through NICENIC INTERNATIONAL GROUP CO., LIMITED, a registrar known for anonymity protection. It resolves to IP address 172.67.188.198 and holds a valid SSL certificate issued by Let’s Encrypt, a combination often used to lend false legitimacy to phishing sites.

Users are strongly advised to avoid interacting with aml-bot.net or any services claiming to provide automated AML compliance via browser-based tools. Do not connect your wallet or enter private keys on this domain. If you have already interacted, immediately revoke wallet permissions, transfer remaining assets to a new wallet, and monitor for unauthorized transactions. Report the domain to PhishDestroy for further analysis and community protection.

Stored source results

Recorded verdicts and infrastructure observations for this domain.

VirusTotal
VirusTotal
0 det.
URLQuery
यूआरएलक्वेरी
1 det.
URLScan
यूआरएलस्कैन
ScamAdviser
Scamadviser
1/100
TLS प्रमाणपत्र
Let's Encrypt
आयु
4 mo
देखी गई स्थिति
सामग्री अनुपलब्ध 502
PhishDestroy
विनाश सूची
सूचीबद्ध
Reports Sent
1
डेटा कवरेज13 recorded checks
VirusTotal checked — no detections recorded यूआरएलक्वेरी 1 det. फ़िशस्टैट्स checked — no match recorded ओटीएक्स no community references सीएफ रडार scan completed URLScan capture संग्रहित रिपोर्ट URLScan verdict विश्लेषण पूरा हुआ डीएनएस ब्लॉक 12 जाँच पूरी — कोई ब्लॉक नहीं TLS valid certificate, 89d कौन है 4 mo old स्क्रीनशॉट 3 captures · 3 sources चेन पुनर्निर्देशित करें जांच नहीं की गई Scamadviser 1/100
नेटवर्क सुरक्षा इंटेलिजेंस Registrar context
Registrar context NiceNIC
Stored registration data identifies NICENIC INTERNATIONAL GROUP CO., LIMITED (IANA 3765) as the registrar. PhishDestroy maintains separate NiceNIC abuse-report research; registrar association is contextual and is not an independent detection for this domain.
NiceNIC Verdict Full Investigation

धमकी प्रतिक्रिया पाइपलाइन

खोज
Checks
Reports
उपलब्धता
15/15
धमकी निगल ली गई
aml-bot.net पहचाना गया और पूर्ण विश्लेषण के लिए कतारबद्ध किया गया
30/03/2026
URLScan.io Capture
Stored URLScan report with capture artifacts
URLScan Verdict
यूआरएलस्कैन विश्लेषण पूरा हुआ; यह वेब-कैप्चर परिणाम पृष्ठ खतरे के फैसले को नहीं बदलता है · score 0
29/07/2026
Cloudflare Radar Report
A stored Cloudflare Radar report is available. The report link alone is not a malicious verdict and does not prove that every network field was captured.
VirusTotal
94 vendors checked on VirusTotal — no vendor detections recorded at check time
31/03/2026
गूगल सुरक्षित ब्राउज़िंग
30/03/2026
ब्लॉकलिस्ट का पता लगाना
में पाया गया 4 blocklists: MetaMask, ScamSniffer, SEAL +1 more
09/08/2026
Registrar Context: NiceNIC
Separate registrar research is available. Registrar association is contextual and is not scored as an independent detection.
Brand Impersonation
Impersonation of Foundation
Forensic Evidence Collected
Stored evidence from URLScan.io, URLQuery, stored screenshot
Technical Analysis Recorded
रिपोर्ट में संग्रहीत प्रौद्योगिकी या फोरेंसिक-विश्लेषण परिणाम शामिल हैं।
09/08/2026
Sent Report Recorded
Stored sent-report record for registrar NICENIC INTERNATIONAL GROUP CO., LIMITED, hosting provider, 1 abuse contact
abuse@nicenic.net
30/03/2026
डिस्ट्रॉयलिस्ट प्रकाशित
30/03/2026
Content Observed Unavailable
नवीनतम संग्रहीत जांच से संकेत मिलता है कि रिपोर्ट की गई सामग्री अनुपलब्ध है; इससे यह स्थापित नहीं होता कि परिवर्तन का कारण कौन या क्या है।
31/03/2026
पहली अनुपलब्धता तक का समय
पता लगाने से लेकर पहले अनुपलब्ध अवलोकन तक 23 घंटे बीत गए।

सार्वजनिक ब्लॉकलिस्ट स्थिति

सहेजा गया कैप्चर

पेज शीर्षक
AMLBot - Comprehensive AML Compliance Solutions for Crypto
Impersonates
Foundation LinkedIn टेलीग्राम YouTube
TLS प्रमाणपत्र
Valid transport encryption · जारीकर्ता Let's Encrypt · valid for 89 days

डोमेन इंटेलिजेंस

डोमेन
URLScan Verdict विश्लेषण पूरा हुआ score 0 report ↗
Telegram IoCs 2 extracted https://t.me/amlbot_support_bot https://t.me/AML_GROUP
सर्वर / ASN cloudflare · AS13335 Cloudflare, Inc.
IP Context Cloudflare shared edge origin IP hidden एज-आईपी प्रतिष्ठा इस डोमेन के लिए जिम्मेदार नहीं है।
रजिस्ट्रार NiceNIC RU(RU) PhishDestroy Investigation
दुरुपयोग संपर्कabuse@nicenic.net
IP पता 172.67.188.198 CDN
भौगोलिक स्थानCA Toronto, CA
नेटवर्कAS13335 · Cloudflare, Inc.
रिवर्स IPviewdns.info → rapiddns.io →
मूल आईपी सीडीएन प्रॉक्सी के पीछे छिपा हुआ है। किनारे के पते के लिए रिवर्स-आईपी परिणामों में असंबंधित किरायेदार शामिल हैं; मूल का पता लगाने के लिए निष्क्रिय DNS या प्रमाणपत्र-पारदर्शिता डेटा की आवश्यकता होती है।
पंजीकरणनिर्मित 30/03/2026 (132d)
HTTP स्थिति502 Error
पहली अनुपलब्धता तक का समय 23h
हम क्या मापते हैं पहली संग्रहीत दुरुपयोग रिपोर्ट से लेकर पहली बार अवलोकन तक कि सामग्री अनुपलब्ध थी, बीता हुआ समय। इससे कारण स्थापित नहीं होता.
प्रत्येक रिपोर्ट में क्या शामिल है संग्रहीत आउटगोइंग-रिपोर्ट रिकॉर्ड उस समय उपलब्ध साक्ष्य का संदर्भ दे सकते हैं, जैसे विक्रेता के फैसले, पंजीकरण डेटा, होस्टिंग विवरण, वर्गीकरण, या स्क्रीनशॉट। यह पृष्ठ किसी प्राप्तकर्ता द्वारा वितरित सटीक पेलोड, रसीद, पावती या कार्रवाई का अनुमान नहीं लगाता है।
तकनीकी विवरणडीएनएस, एसएसएल एसएएन, टाइमस्टैम्प
पहली बार पता चला30/03/2026
DOM Analysisanalyzed 29/07/2026score 55/1004 brand signals
IoC Extractionscanned 01/08/20260 wallet · 2 Telegram IoCs
Submitted URLhttps://aml-bot.net/
नेमसर्वरdonald.ns.cloudflare.com
TLS Fingerprint
TLS Observationvalid from 29/03/2026scanned 31/03/2026
Case ID
ICANN OVERSIGHT

प्रत्यायन और आरएए संदर्भ

Registrar accreditation and DNS abuse obligations

For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.

Accreditation is a contract, not a safety certification.

RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.

मान्यता एक अनुबंध है, सुरक्षा की मुहर नहीं। ICANN शुल्क सत्यापित करें RAA §3.18 पढ़ें PHISHDESTROY INVESTIGATIONICANN funding, contracts, and DNS abuse oversight
Accountability draft कुछ भी अपने आप नहीं भेजा जाता।

Latest Classified Outcome 2026-08-09 03:45:45 UTC

Primary outcome Registration hold observed reason: Registrar clientHold 95% confidence
Attribution NICENIC INTERNATIONAL GROUP CO., LIMITED mechanism: Registrar clientHold source: Rdap Status Collector
Evidence layers Availability: DNS inactive Content: Unreachable DNS: NXDOMAIN Registration: Registrar clientHold
Latest HTTP observation अज्ञात Origin unreachable Http 5xx 20% 2026-08-09 01:33:12 UTC
RDAP registration Registrar clientHold NICENIC INTERNATIONAL GROUP CO., LIMITED · IANA 3765 RDAP HTTP 200 source: Rdap Status Collector clientDeleteProhibitedclientHoldclientTransferProhibited expires 2027-03-29 12:44:32 UTC checked 2026-08-09 03:45:45 UTC
Registrar action marker verified clientHold marker NICENIC INTERNATIONAL GROUP CO., LIMITED · IANA 3765 causal link to our report not established
Observed timeline last reachable: 2026-04-21 22:24:43 UTC current episode first observed: 2026-08-05 01:45:38 UTC observed RIP window: 2026-04-21 22:24:43 UTC → 2026-08-05 01:45:38 UTC · 2,523.35h midpoint estimate ≈ 2026-06-13 12:05:10 UTC · precision very low · basis bounded
Availability, content, DNS and registration are independent evidence layers. NXDOMAIN, an unreachable origin or missing content alone does not prove registrar action. A registrar or provider is credited only when a direct technical marker identifies that actor. Report causality is shown separately.

फॉरेंसिक इंटेलिजेंस

External Scripts 1
https://performance.radar.cloudflare.com/beacon.js
तकनीकें · 21 identified
Node.js
Programming languages

JavaScript runtime built on Chrome V8 engine for server-side development.

Bootstrap
UI frameworks

Popular CSS framework for responsive, mobile-first web development.

React
JavaScript frameworks

JavaScript library for building user interfaces with component-based architecture.

Next.js
JavaScript frameworks SSR

React framework for production with hybrid static and server rendering.

Twitter Ads

Conversion and audience tracking pixel for paid campaigns on X (Twitter) — signals that the site runs paid X ads.

business.x.com
Trustpilot
SweetAlert2
R
Reddit Ads
M
Microsoft Advertising
J
jsDelivr
CDN

Free public CDN for open-source projects, serving files from npm and GitHub.

H
HubSpot Analytics
Hotjar

User-behavior analytics: heatmaps, session recordings, on-site surveys.

HSTS
सुरक्षा

HTTP Strict Transport Security — forces browsers to use HTTPS connections only.

Google Tag Manager
Tag managers

Tag management system for deploying marketing and analytics tags.

tagmanager.google.com
Google Analytics
Analytics

Web analytics service tracking website traffic and user behavior.

marketingplatform.google.com
Facebook Pixel

Conversion-tracking pixel by Meta — logs page views and custom events to Facebook/Instagram ad accounts.

www.facebook.com
Cookiebot
Cloudflare Browser Insights
Analytics RUM

Performance monitoring tool that measures website speed from real users.

www.cloudflare.com
Cloudflare
CDN

Web infrastructure and security company providing CDN, DDoS mitigation, and DNS services.

www.cloudflare.com
Webpack
Build tools

Module bundler for modern JavaScript applications.

HTTP/3
Miscellaneous

Third major version of HTTP protocol, built on QUIC for faster, more reliable connections.

Detected via क्लाउडफ्लेयर रडार · Wappalyzer engine
इस डोमेन की रिपोर्ट करें सबूत जमा करें और दूसरों की सुरक्षा में मदद करें

वायरसटोटल विश्लेषण

0 / 94 सुरक्षा विक्रेताओं ने इस डोमेन को चिह्नित किया
View on VT
Last analyzed
No VirusTotal engine marked the domain malicious in the stored analysis.
साइट प्रदर्शन विश्लेषण

Google PageSpeed Insights — mobile performance audit of aml-bot.net · checked Mar 30, 2026

33
Poor
Performance
FCP
6.57s
First Contentful Paint
LCP
11.33s
Largest Contentful Paint
CLS
0
Cumulative Layout Shift
TBT
1385ms
Total Blocking Time
SI
7.48s
Speed Index
Powered by Google PageSpeed Insights · Mobile strategy · Scores: 90-100 Good 50-89 Needs Work 0-49 Poor
साक्ष्य और बाहरी रिपोर्टेंIndependent lookups and source reports
Community Scam Report — ChainAbuse
4 reports filed for aml-bot.net (4 written by people) · category: Phishing · source checked
“Malicious Website”
— reported by Anonymous Trusted reporter on Jul 11, 2023 · Source: ChainAbuse (TRM Labs) — full report and evidence there.
Submitted Evidence Snapshot
Sent: Ledger records: 1 Case ID: PD-20260330-6364D6 Recipient: abuse@nicenic.net, abuse@verisign-grs.com, compliance@icann.org
Page title stored with report: AMLBot - Comprehensive AML Compliance Solutions for Crypto
Blocklist hits included with submission: धोखाधड़ी-खोजी
Victim safety and official reportingImmediate actions and verified reporting channels
If credentials were compromised, report immediately. Do not engage with recovery scammers.

यदि आपने खाता क्रेडेंशियल, व्यक्तिगत या भुगतान जानकारी दर्ज की है, या इस डोमेन से कोई फ़ाइल डाउनलोड की है, तो तुरंत कार्रवाई करें। घटना की रिपोर्ट करने और अपनी सुरक्षा करने में आपकी सहायता के लिए नीचे संसाधन दिए गए हैं।

यूरोपोल
अपने ईयू देश के लिए आधिकारिक रिपोर्टिंग चैनल ढूंढें
National police directory
रिकवरी ठगों से सावधान रहें! अपराधी जांचकर्ता, वकील या रिकवरी एजेंट होने का नाटक करते हुए पीड़ितों से दोबारा संपर्क कर सकते हैं। अग्रिम शुल्क का भुगतान न करें या क्रेडेंशियल साझा न करें। रिकवरी धोखाधड़ी के बारे में और जानें →

अपने स्थानीय अधिकारियों को रिपोर्ट करें

आधिकारिक साइबर अपराध संपर्क, या एक शिकायत ड्राफ्ट बनाएं → प्राप्त करने के लिए अपना देश चुनें।

97-देश निर्देशिका
एआई-सहायता प्राप्त ड्राफ्ट - घटना विवरण एआई प्रदाता द्वारा संसाधित किया जाता है इसकी स्वयं समीक्षा करें और सबमिट करें
इस रिपोर्ट को एम्बेड करेंRead-only HTML widget
HTML · IFRAME

इस रिपोर्ट को एम्बेड करें

इस थ्रेट इंटेलिजेंस को अपनी वेबसाइट या ब्लॉग पर साझा करें।

embed.html
<iframe
  src="https://phishdestroy.io/hi/embed/domain/aml-bot.net"
  title="PhishDestroy threat report for aml-bot.net"
  width="100%" height="320"
  loading="lazy"
  referrerpolicy="no-referrer"
  sandbox="allow-same-origin allow-popups allow-popups-to-escape-sandbox"
  style="border:0;border-radius:12px;max-width:100%"
></iframe>

एक अत्यंत सच्चा धन्यवाद-पत्र

व्यंग्यात्मक मसौदा जनरेटर

प्राप्तकर्ता
शुल्क संदर्भ

यह व्यंग्यात्मक मसौदा है। शुल्क के आंकड़े अनुमान हैं; इन्हें इस डोमेन से ठीक-ठीक जोड़ने का दावा नहीं किया जाता।