Notification and current-status evidence
The sent-report ledger records the first outgoing report at .
The recorded recipient is abuse@globconnex.com.
The latest stored availability evidence still shows the domain reachable; 4 months has elapsed since the first outgoing report.
ICANN RAA §3.18 describes registrar abuse-contact and handling obligations. This section records outgoing timestamps, listed recipients, case identifiers, and later availability. It does not by itself prove receipt, acknowledgement, investigation, remediation, or contractual non-compliance.
amlpro[.]cx
amlpro.cx की फ़िशिंग और सुरक्षा जाँच
“AML Crypto Risk Checker for BTC, USDT, ETH, TON and other coins”
amlpro.cx — सर्वर त्रुटि (HTTP 502). घोटाले का प्रकार: Investment Scam. साक्ष्य सारांश: VirusTotal 14/91 (ADMINUSLabs, alphaMountain.ai, BitDefender, Chong Lua Dao, CRDF); URLQuery 1 alert; Spamhaus DBL_PHISH; PhishDestroy score 95/100. रजिस्ट्रार: CentralNic.
मूल फॉरेंसिक रिकॉर्ड सुरक्षित रखने के लिए नीचे का विस्तृत PhishDestroy AI विश्लेषण अंग्रेज़ी में रखा गया है।
The domain amlpro.cx was registered on March 24, 2026 through CentralNic Ltd and resolves to the IPv4 address 147.45.217.248, which is hosted by Global Connectivity Solutions LLP in Lithuania. DNS resolution uses the Cloudflare authoritative name servers janet.ns.cloudflare.com and tadeo.ns.cloudflare.com. An SSL certificate issued by Let’s Encrypt (CN=E7) was observed, indicating HTTPS support. The site presented the page title "AML Crypto Risk Checker for BTC, USDT, ETH, TON and other coins," which aligns with the classified scam type of an investment‑related phishing campaign.
Technical fingerprints show the server runs Ubuntu with Nginx and serves assets from the Unpkg CDN. Security analysis reveals that four of ninety‑four VirusTotal scanners flagged the domain, and it appears on a single external blocklist. PhishDestroy has listed the domain as blocked, and Gridinsoft assigned a trust score of 0 out of 100, reflecting a high confidence of malicious intent.
The current operational status is offline, limiting immediate interaction but suggesting the infrastructure may be re‑activated. Defenders should continue to block the domain and its hosting IP, add the IP to network‑level deny lists, and monitor for any re‑hosting on alternative infrastructure. Given the elevated risk rating and the investment‑scam classification, threat‑hunters are advised to incorporate amlpro.cx into threat‑intel feeds, enforce URL filtering, and watch for related indicators such as the Let’s Encrypt certificate fingerprint and the use of the Unpkg CDN in future campaigns.
नेटवर्क सुरक्षा इंटेलिजेंस
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| DNS4EU | amlpro.cx |
malicious | Sinkholed |
धमकी प्रतिक्रिया पाइपलाइन
सार्वजनिक ब्लॉकलिस्ट स्थिति
तकनीकें · 3 identified
High-performance HTTP server and reverse proxy, known for stability and low resource usage.
Fast CDN for everything on npm — serves raw files from npm packages.
वायरसटोटल विश्लेषण
साइट प्रदर्शन विश्लेषण
Google PageSpeed Insights — mobile performance audit of amlpro.cx · checked Mar 24, 2026
साक्ष्य और बाहरी रिपोर्टें
PD-20260324-7DF6B9 Recipient: abuse@globconnex.com क्या आप इस साइट से प्रभावित हुए?
यदि आपने खाता क्रेडेंशियल, व्यक्तिगत या भुगतान जानकारी दर्ज की है, या इस डोमेन से कोई फ़ाइल डाउनलोड की है, तो तुरंत कार्रवाई करें। घटना की रिपोर्ट करने और अपनी सुरक्षा करने में आपकी सहायता के लिए नीचे संसाधन दिए गए हैं।
अपने स्थानीय अधिकारियों को रिपोर्ट करें
आधिकारिक साइबर अपराध संपर्क, या एक शिकायत ड्राफ्ट बनाएं → प्राप्त करने के लिए अपना देश चुनें।
किसी भी डोमेन की जाँच करें
संग्रहीत ब्लॉकलिस्ट, WHOIS, DNS और सार्वजनिक स्कैन साक्ष्य का उपयोग करके खतरे का विश्लेषण
अभी स्कैन करेंफ़िशिंग की रिपोर्ट करें
संदिग्ध डोमेन हमारे थ्रेट डेटाबेस में जमा करें — समुदाय की सुरक्षा करें
रिपोर्ट करेंसीधा खतरा फीड
हाल की फ़िशिंग रिपोर्टें और उपलब्धता में परिवर्तन देखे गए
निगरानी करेंजानकारी में रहें, सुरक्षित रहें
लाइव खतरों की निगरानी करें या यदि आपको लगता है कि यह एक गलत सकारात्मक है तो इस लिस्टिंग को चुनौती दें।