MALICIOUS — CRITICAL
aml-coinanalysis[.]com
Analysis of aml-coinanalysis.com indicates a high-risk brand impersonation domain targeting AMLBot, a cryptocurrency transaction monitoring service.
- VirusTotal
- 4/91
- Blocklists
- No stored match
- उपलब्धता
- अंतिम ज्ञात सक्रिय · HTTP 301
Do not enter credentials, seed phrases, payment details, or personal information on this domain.
Notification and current-status evidence
The sent-report ledger records the first outgoing report at .
The recorded recipient is rtr-security-threats@realtimeregister.com.
The latest stored availability evidence still shows the domain reachable; 6 months has elapsed since the first outgoing report.
ICANN RAA §3.18 describes registrar abuse-contact and handling obligations. This section records outgoing timestamps, listed recipients, case identifiers, and later availability. It does not by itself prove receipt, acknowledgement, investigation, remediation, or contractual non-compliance.
Jump to section
aml-coinanalysis.com — अंतिम ज्ञात सक्रिय (HTTP 301). ब्रांड प्रतिरूपण: AMLBot; घोटाले का प्रकार: Crypto Scam. साक्ष्य सारांश: VirusTotal 4/91 (alphaMountain.ai, Forcepoint ThreatSeeker, Gridinsoft, SOCRadar); PhishDestroy score 77/100. रजिस्ट्रार: Realtime.
मूल फॉरेंसिक रिकॉर्ड सुरक्षित रखने के लिए नीचे का विस्तृत PhishDestroy AI विश्लेषण अंग्रेज़ी में रखा गया है।
Evidence Analysis
Analysis of aml-coinanalysis.com indicates a high-risk brand impersonation domain targeting AMLBot, a cryptocurrency transaction monitoring service. The domain was registered on February 21, 2026, through Realtime Register B.V. and currently resolves to IP 178.130.46.159, hosted on AS215540 (GLOBAL CONNECTIVITY SOLUTIONS LLP) in the Netherlands. The page title, 'Crypto AML Check - Cryptocurrency Transaction Monitoring Solution | Sumsub,' suggests an attempt to mimic legitimate AML compliance tools, though the exact content and functionality remain unconfirmed as the site has not been directly analyzed. Infrastructure reveals Cloudflare nameservers (adel.ns.cloudflare.com, jerome.ns.cloudflare.com) and a Let's Encrypt SSL certificate (R12), with backend technologies including React and Nginx. The domain is flagged by at least one security blocklist, including PhishDestroy, and appears in a single AlienVault OTX threat intelligence pulse. Scamadviser and Gridinsoft assign trust scores of 1/100 and 0/100, respectively, reinforcing its classification as a crypto scam. VirusTotal reports 4 of 93 security vendors detecting malicious activity, though this does not represent exhaustive validation. Defenders should treat this domain as active and malicious, particularly in environments handling cryptocurrency or AML compliance tools. The 301 HTTP status suggests possible redirection to further malicious infrastructure. Given the registration date, Cloudflare proxy, and low detection rates, this appears to be a recently deployed campaign with limited visibility. Blocking the domain and associated IP, monitoring for related subdomains or SSL certificates, and alerting users to potential brand impersonation risks are recommended actions.
डेटा कवरेज13 recorded checks
सुरक्षा संकेत
नेटवर्क सुरक्षा इंटेलिजेंस
धमकी प्रतिक्रिया पाइपलाइन
सार्वजनिक ब्लॉकलिस्ट स्थिति
सहेजा गया कैप्चर
डोमेन इंटेलिजेंस
तकनीकी विवरणडीएनएस, एसएसएल एसएएन, टाइमस्टैम्प
ICANN OVERSIGHT
प्रत्यायन और आरएए संदर्भ
प्रत्यायन और आरएए संदर्भ
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
तकनीकें · 2 identified
JavaScript library for building user interfaces with component-based architecture.
High-performance HTTP server and reverse proxy, known for stability and low resource usage.
वायरसटोटल विश्लेषण
संग्रहीत साक्ष्य
साइट प्रदर्शन विश्लेषण
Google PageSpeed Insights — mobile performance audit of aml-coinanalysis.com · checked Jun 27, 2026
साक्ष्य और बाहरी रिपोर्टेंIndependent lookups and source reports
PD-20260206-DE3AD8 Recipient: rtr-security-threats@realtimeregister.com Victim safety and official reportingImmediate actions and verified reporting channels
यदि आपने खाता क्रेडेंशियल, व्यक्तिगत या भुगतान जानकारी दर्ज की है, या इस डोमेन से कोई फ़ाइल डाउनलोड की है, तो तुरंत कार्रवाई करें। घटना की रिपोर्ट करने और अपनी सुरक्षा करने में आपकी सहायता के लिए नीचे संसाधन दिए गए हैं।
अपने स्थानीय अधिकारियों को रिपोर्ट करें
आधिकारिक साइबर अपराध संपर्क, या एक शिकायत ड्राफ्ट बनाएं → प्राप्त करने के लिए अपना देश चुनें।