amlchekeer[.]icu
“AML Bot - Network Selector”
Riepilogo delle prove
The domain amlchekeer.icu is a confirmed phishing site engaged in brand impersonation targeting AMLBot, a cryptocurrency compliance service. It presents itself as a legitimate AMLBot portal under the page title 'AML Bot - Network Selector' but is designed to deceive users into disclosing sensitive information or transferring cryptocurrency under false pretenses. As of the latest verification, amlchekeer.icu has been taken offline, though it previously operated as a cryptocurrency scam with no associated drainer kit identified.
Technical indicators for amlchekeer.icu show limited detection at the time of analysis. The domain registered a creation date of 2026-02-21 07:01:08 and resolves to the IP address 172.67.221.231, hosted on Cloudflare's network in the US. Security scans returned 0 of 95 detections on VirusTotal, and Google Safe Browsing did not flag the domain. However, it appears on 1 security blocklist (PhishDestroy). The SSL certificate is issued by WE1, and no registrar information is currently available.
Users who may have interacted with amlchekeer.icu should take immediate steps to secure their accounts and assets. For cryptocurrency-related exposure, revoke any active token approvals and transfer funds to a new wallet to prevent unauthorized access. If credentials were entered, change passwords immediately and enable two-factor authentication on all relevant accounts. Report the phishing domain to platforms like Google Safe Browsing, PhishTank, or the impersonated brand (AMLBot) to aid in broader mitigation efforts.
Data Coverage
Pipeline di risposta alle minacce
Copertura delle blocklist
10 fonti esterne monitorate · snapshot del 13/08/2026
10 fonti esterne monitorate Nessuna corrispondenza
Acquisizione salvata
Analisi dei domini
Dettagli tecniciDNS, nomi TLS e date
ZONA SHORTDOT · PROVE PUBBLICHE
.icu
ShortDot zone evidence
ShortDot zone evidence
The linked repository preserves daily zone observations across seven ShortDot-operated TLDs, including registration volume and abuse-related indicators. This registry context is supporting background and is not an independent detection for the domain in this report.
Analisi di VirusTotal
Questo sito ti ha influenzato in qualche modo?
Se hai inserito credenziali dell'account, informazioni personali o di pagamento oppure hai scaricato un file da questo dominio, agisci immediatamente. Di seguito sono riportate le risorse per aiutarti a segnalare l'incidente e proteggerti.
Segnalalo alle autorità locali
Seleziona il tuo Paese per ottenere contatti ufficiali del crimine informatico o creare una bozza di reclamo →.
Verifica qualsiasi dominio
Analisi delle minacce utilizzando blocklist archiviate, WHOIS, DNS e prove di scansione pubblica
Scansiona oraSegnala un tentativo di phishing
Segnala i domini sospetti al nostro database delle minacce — proteggi la comunità
SegnalaFeed in tempo reale sulle minacce
Segnalazioni recenti di phishing e modifiche osservate della disponibilità
MonitoraRimani informato, rimani al sicuro
Controlla le minacce in tempo reale oppure contesta questa segnalazione se ritieni che si tratti di un falso positivo