aml-trn[.]com
“AML Check”
साक्ष्य सारांश
Analysis of the domain aml-trn.com indicates it was actively involved in a wallet and seed phishing campaign targeting users of the cryptocurrency exchange Bitget. The domain was registered on May 29, 2025, through Web Commerce Communications Limited and resolved to the IP address 104.21.56.176, hosted on Cloudflare's network (AS13335). Infrastructure analysis reveals the use of Cloudflare nameservers (DONNA.NS.CLOUDFLARE.COM and NASH.NS.CLOUDFLARE.COM), a common tactic to obscure hosting origins and evade takedowns. No SSL certificate was detected, increasing the likelihood of interception or manipulation of user data in transit. The page title, 'AML Check,' suggests the site impersonated a Know Your Customer (KYC) or Anti-Money Laundering (AML) verification process, a technique frequently employed to harvest wallet seeds or credentials under the guise of compliance.
The domain was flagged by one security blocklist and identified by PhishDestroy as part of a wallet/seed phishing operation. As of July 22, 2026, the domain is offline, though its prior activity and infrastructure remain relevant for retrospective detection. Two of 95 security vendors on VirusTotal flagged the domain as malicious, providing additional corroboration of its harmful intent. Defenders should treat this domain as a confirmed threat vector for cryptocurrency-related phishing.
Indicators of compromise (IOCs) include the domain name, IP address 104.21.56.176, and the 'AML Check' page title. Network security teams are advised to block or monitor traffic to this domain and its associated IP, particularly in environments where Bitget or similar platforms are used. Given the domain's use of Cloudflare, further investigation into related infrastructure may uncover additional malicious assets. The absence of an SSL certificate and the domain's presence on a security blocklist further justify its classification as a high-risk artifact, even in its current offline state.
Data Coverage
धमकी प्रतिक्रिया पाइपलाइन
ब्लॉकलिस्ट कवरेज
10 निगरानी वाले बाहरी स्रोत · संग्रहीत स्नैपशॉट 10/08/2026
पहचान समयरेखा
-
Cloudflare Radar
Cloudflare Radar स्कैन संग्रहीत · स्कैन खोलें
सहेजा गया कैप्चर
डोमेन इंटेलिजेंस
तकनीकी विवरणDNS, TLS नाम और समय-मुद्राएँ
ICANN OVERSIGHT
प्रत्यायन और आरएए संदर्भ
प्रत्यायन और आरएए संदर्भ
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
वायरसटोटल विश्लेषण
क्या आप इस साइट से प्रभावित हुए?
यदि आपने खाता क्रेडेंशियल, व्यक्तिगत या भुगतान जानकारी दर्ज की है, या इस डोमेन से कोई फ़ाइल डाउनलोड की है, तो तुरंत कार्रवाई करें। घटना की रिपोर्ट करने और अपनी सुरक्षा करने में आपकी सहायता के लिए नीचे संसाधन दिए गए हैं।
अपने स्थानीय अधिकारियों को रिपोर्ट करें
आधिकारिक साइबर अपराध संपर्क, या एक शिकायत ड्राफ्ट बनाएं → प्राप्त करने के लिए अपना देश चुनें।
किसी भी डोमेन की जाँच करें
संग्रहीत ब्लॉकलिस्ट, WHOIS, DNS और सार्वजनिक स्कैन साक्ष्य का उपयोग करके खतरे का विश्लेषण
अभी स्कैन करेंफ़िशिंग की रिपोर्ट करें
संदिग्ध डोमेन हमारे थ्रेट डेटाबेस में जमा करें — समुदाय की सुरक्षा करें
रिपोर्ट करेंसीधा खतरा फीड
हाल की फ़िशिंग रिपोर्टें और उपलब्धता में परिवर्तन देखे गए
निगरानी करेंजानकारी में रहें, सुरक्षित रहें
लाइव खतरों की निगरानी करें या यदि आपको लगता है कि यह एक गलत सकारात्मक है तो इस लिस्टिंग को चुनौती दें।