api-amlbot[.]xyz
“Pay, Send and Save Money with PayPal | PayPal US”
संग्रहीत पहचान
क्लोकिंग चेतावनी
- क्लोकिंग प्रकार
status_split- क्लोकिंग स्कोर
- 2/6
साक्ष्य सारांश
PhishDestroy identifies api-amlbot.xyz as an active crypto drainer scam designed to trick cryptocurrency users into connecting their wallets and unknowingly transferring funds to attacker-controlled accounts. This malicious domain mimics legitimate crypto-asset management interfaces, presenting fake transaction approvals or balance displays that prompt victims to sign malicious blockchain transactions. Once a user connects a wallet and approves a transaction, the drainer silently transfers tokens to addresses controlled by the threat actor, often moving funds across multiple blockchains to obfuscate the trail. The domain is currently resolving to IP 188.114.96.3 and has been actively serving malicious content since its registration.
This domain was flagged by PhishDestroy with elevated risk status after 4 out of 95 VirusTotal security vendors identified it as malicious. api-amlbot.xyz was registered on January 22, 2026 through NICENIC INTERNATIONAL GROUP CO., LIMITED, and currently holds an SSL certificate issued by Google Trust Services, a tactic commonly used to appear legitimate and evade browser warnings. The combination of a newly registered domain, low detection rate on public scanners, and hosting on a bulletproof IP address indicates this is a recently deployed, targeted operation likely aimed at users searching for crypto-related tools or services.
If you visited api-amlbot.xyz or connected your wallet to it, immediately revoke any connected permissions using your wallet’s “Revoke Permissions” or “Connected Apps” feature, and transfer your remaining funds to a new, isolated wallet. Do not interact with any further prompts from the site. Report the domain to PhishDestroy for investigation and consider scanning your device with updated antivirus software. Always verify the authenticity of crypto tools by checking PhishDestroy’s database before use, and never approve transactions from unknown or untrusted websites.
Data Coverage
नेटवर्क सुरक्षा इंटेलिजेंस
धमकी प्रतिक्रिया पाइपलाइन
ब्लॉकलिस्ट कवरेज
10 निगरानी वाले बाहरी स्रोत · संग्रहीत स्नैपशॉट 11/08/2026
सहेजा गया कैप्चर
डोमेन इंटेलिजेंस
तकनीकी विवरणDNS, TLS नाम और समय-मुद्राएँ
ICANN OVERSIGHT
प्रत्यायन और आरएए संदर्भ
प्रत्यायन और आरएए संदर्भ
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
वायरसटोटल विश्लेषण
साइट प्रदर्शन विश्लेषण
Google PageSpeed Insights — mobile performance audit of api-amlbot.xyz · checked Apr 15, 2026
क्या आप इस साइट से प्रभावित हुए?
यदि आपने खाता क्रेडेंशियल, व्यक्तिगत या भुगतान जानकारी दर्ज की है, या इस डोमेन से कोई फ़ाइल डाउनलोड की है, तो तुरंत कार्रवाई करें। घटना की रिपोर्ट करने और अपनी सुरक्षा करने में आपकी सहायता के लिए नीचे संसाधन दिए गए हैं।
अपने स्थानीय अधिकारियों को रिपोर्ट करें
आधिकारिक साइबर अपराध संपर्क, या एक शिकायत ड्राफ्ट बनाएं → प्राप्त करने के लिए अपना देश चुनें।
किसी भी डोमेन की जाँच करें
संग्रहीत ब्लॉकलिस्ट, WHOIS, DNS और सार्वजनिक स्कैन साक्ष्य का उपयोग करके खतरे का विश्लेषण
अभी स्कैन करेंफ़िशिंग की रिपोर्ट करें
संदिग्ध डोमेन हमारे थ्रेट डेटाबेस में जमा करें — समुदाय की सुरक्षा करें
रिपोर्ट करेंसीधा खतरा फीड
हाल की फ़िशिंग रिपोर्टें और उपलब्धता में परिवर्तन देखे गए
निगरानी करेंजानकारी में रहें, सुरक्षित रहें
लाइव खतरों की निगरानी करें या यदि आपको लगता है कि यह एक गलत सकारात्मक है तो इस लिस्टिंग को चुनौती दें।