VirusTotal
3 / 91
“amlcheker.digital | 521: Web server is down”
amlcheker.digital — Belum terverifikasi. Jenis penipuan: Crypto Scam. Ringkasan bukti: VirusTotal 3/91 (alphaMountain.ai, Chong Lua Dao, Gridinsoft); URLQuery 2 alerts; PhishDestroy score 81/100. Registrar: Web Commerce Communica….
Analisis terperinci PhishDestroy AI di bawah tetap berbahasa Inggris untuk menjaga catatan forensik asli.
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| Hagezi Threat Feed | amlcheker.digital |
malicious | Sinkholed |
| DNS4EU | amlcheker.digital |
malicious | Sinkholed |
The domain amlcheker.digital was registered on 2026-02-21 through Web Commerce Communications Limited and remains active as of the 2026-07-12 assessment. The site returns HTTP 521, indicating the origin web server is down, and the page title reports “amlcheker.digital | 521: Web server is down”. The domain is currently listed on one security blocklist and has been blocked by PhishDestroy, reflecting a high‑risk classification.
Infrastructure inspection shows the domain resolves to IP address 104.21.55.173, which belongs to Cloudflare, Inc. (AS13335) and is located in the United States. DNS resolution uses the Cloudflare authoritative nameservers bowen.ns.cloudflare.com and rayne.ns.cloudflare.com. The service is presenting an SSL certificate issued by Google Trust Services under the WE1 label, confirming the use of TLS. HTTP/3 support is also detected, consistent with Cloudflare’s edge platform.
Threat intelligence indicates a cryptocurrency‑related generic phishing campaign. VirusTotal analysis recorded one positive detection out of ninety‑five scanners, suggesting that at least one security vendor has flagged the domain for malicious activity. No additional malware kits or brand impersonation details are available beyond the generic phishing label, leaving the exact payload or victim interaction unknown.
Defenders should prioritize blocking amlcheker.digital at perimeter and DNS layers, given its high‑risk status and active blocklist presence. Continuous monitoring of the associated IP 104.21.55.173 for new domains or changes in Cloudflare configuration is advised. Organizations should also update email and web filtering rules to flag any communications referencing the domain, especially those promising cryptocurrency rewards.
Data pengamatan perbandingan crawler versus browser yang telah disimpan untuk host ini, ditambah pemeriksaan sidik jari secara real-time untuk sistem distribusi lalu lintas bergaya Keitaro.
Catatan pemindai: unavailable: raw=connection_error; http=0; via=http_proxy; error=SOCKSHTTPConnectionPool(host='amlcheker.digital', port=80): Max retries exceeded with url: / (Caused by NewConnectionErr
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Reputasi Edge-IP tidak dikaitkan dengan domain ini.
rayne.ns.cloudflare.comLocation describes the IP network.
73fd56322b3be95f74bcc2c3c2f3f592e4af75101b2d9bb7debd97ebe49773faSaved certificate metadata. Certificate dates without a timezone are shown as stored. Transport encryption does not establish that the site is trustworthy.
9 recorded events. These records describe collected evidence, outgoing notifications and publication; they do not confirm a complete investigation or a takedown.
We scan suspicious URLs, inspect public results and send evidence through the appropriate abuse-reporting channels. The dated events above show what is recorded for this domain. The directory below explains the wider workflow.
Capture the rendered page, requests and visible infrastructure.
Compare the available engine results and retain the analysis timestamp.
Check whether Google currently lists the URL as unsafe.
Inspect a public scan and its recorded network and classification data.
Look for indicator references and related community intelligence.
Compare archived captures and preserve historical context.
Look for matching indicators and associated threat records.
Inspect certificate records and related hostnames.
Compare security resolver responses and record observed blocking.
Inspect the public DNS, TLS, HTTP and technology surface.
Security services used for scanning, reputation checks and reporting are listed below. A service being listed is not evidence that it received, accepted or acted on this particular domain. Recorded submissions appear in the notification history above.
Dilaporkan oleh 1 anggota komunitas; pertama terlihat 08/09/2025
Jika Anda memasukkan kredensial akun, informasi pribadi atau pembayaran, atau mengunduh file dari domain ini, segera ambil tindakan. Di bawah ini adalah sumber daya untuk membantu Anda melaporkan insiden tersebut dan melindungi diri Anda sendiri.
Pilih negara Anda untuk mendapatkan kontak resmi kejahatan dunia maya, atau membuat draf pengaduan →.
Template-based draft · optional AI wording assistance requires separate consent
Analisis ancaman menggunakan daftar blokir yang disimpan, WHOIS, DNS, dan bukti pemindaian publik
Pindai SekarangLaporkan domain yang mencurigakan ke basis data ancaman kami — lindungi komunitas
LaporanLaporan phishing terbaru dan perubahan ketersediaan yang diamati
PantauPantau ancaman secara langsung atau ajukan keberatan terhadap daftar ini jika Anda yakin ini merupakan false positive