amlradar[.]org
amlradar.org のフィッシング・安全性チェック
amlradar.org — コンテンツが利用できません (HTTP 502). 詐欺タイプ: Crypto Scam. 証拠の概要: VT 5/93 (alphaMountain.ai, Chong Lua Dao, CyRadar, Forcepoint ThreatSeeker, Gridinsoft); URLQuery 4 alerts; URLScan no malicious verdict; GSB no flag; BL 0; PD 78/100. レジストラ: CNOBIN INFORMATION TEC….
元のフォレンジック記録を保持するため、下の PhishDestroy AI 詳細分析は英語のままです。
The domain amlradar.org has been identified as a generic phishing portal designed to mimic legitimate anti-money-laundering (AML) compliance platforms. Analysis indicates this infrastructure was likely used to harvest credentials or distribute fraudulent financial alerts, though no specific financial institution or regulatory body is directly impersonated. The domain is currently offline, but prior activity suggests it targeted individuals or organizations required to comply with AML regulations, potentially exploiting urgency around compliance deadlines to prompt user interaction. Infrastructure analysis reveals the domain was registered on February 21, 2026, through CNOBIN INFORMATION TECHNOLOGY LIMITED, an entity frequently associated with high-risk registrations. It resolved to the IP address 104.21.42.191, a Cloudflare proxy endpoint commonly used to obscure hosting origins. At the time of detection, the domain was flagged by 5 of 95 security vendors on VirusTotal, with a Gridinsoft trust score of 0/100. It also appeared on one security blocklist, and its page title, 'Just a moment...', is consistent with transient or cloaked phishing pages attempting to evade automated detection. The creation date, set in the future, further suggests an attempt to bypass age-based reputation filters. Current status indicates the domain has been taken offline, likely following enforcement action or abandonment by the operators. However, the underlying infrastructure may remain active or be repurposed for similar campaigns. Organizations and individuals are advised to treat any prior interaction with this domain as a potential security incident. Network administrators should block the domain and its resolving IP at perimeter defenses, while end users should verify the legitimacy of AML-related communications through official channels only. Monitoring for related domains registered via the same registrar or resolving to the same IP range is recommended to preemptively mitigate follow-up threats.
ネットワークセキュリティインテリジェンス
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| Nextron YARA rules | amlradar.org/assets/index-bakr55ut.js |
malware | Unique code from Jetriz, Swid & Jeniva of the Tetris framework |
| Nextron YARA rules | amlradar.org/assets/index-te6_j_jh.js |
malware | Unique code from Jetriz, Swid & Jeniva of the Tetris framework |
| DNS4EU | stool-overlay.commontechrepo.cc |
malicious | Sinkholed |
| DigiCert UltraDNS | tonapi.io |
malicious | Sinkholed |
脅威対応 Pipeline
公開ブロックリスト登録状況
保存済みキャプチャ
ドメイン・インテリジェンス
技術的な詳細DNS、SSL SAN、タイムスタンプ
ICANN OVERSIGHT
認定と RAA の背景
認定と RAA の背景
ICANNには支払いが済んだ。説明責任は届かなかった。
このgTLDでは、上記のレジストラはICANNとの契約に基づいて運営されています。ICANNは、登録、更新、移管に連動する年間手数料、変動手数料、および取引ベースの手数料を徴収します。
認定:収益化済み。説明責任:後ほどもう一度ご確認ください。
そして魔法が始まります。ICANNがRAA §3.18を書き、レジストラは自らの顧客基盤内の不正利用を自ら調査し、被害者は証拠を無償で提供する一方、各層は誰か別の者が動くのを待ちます。それで被害者が少しでも安全になった気がするなら、結構なことです――請求書は仕事を果たしたわけです。
フォレンジックインテリジェンス
VirusTotalによる分析
証拠および外部報告書
このサイトによって何か影響を受けましたか?
アカウント資格情報、個人情報、支払い情報を入力した場合、またはこのドメインからファイルをダウンロードした場合は、すぐに対処してください。インシデントを報告し、自分自身を守るのに役立つリソースを以下に示します。
お住まいの地域の当局へ報告してください
サイバー犯罪の公式連絡先 または 苦情草稿を作成する → を取得するには、国を選択してください。
このレポートについて: amlradar.org
このレポートは、PhishDestroy が入手できる最新の保管証拠を示します。ソースのタイムスタンプが利用可能な場合には表示されます。入手可能性とベンダーの判断は収集後に変更される可能性があります。
2026年8月7日 の時点で、amlradar.org は 5 セキュリティ エンジンから検出されました。
このリストが不正確であると思われる場合は、異議申し立てを提出する までご連絡ください。当社の方法論について詳しくは、よくある質問ページ をご覧ください。
任意のドメインを確認する
保存されたブロックリスト、WHOIS、DNS、および公開スキャン証拠を使用した脅威分析
今すぐスキャンフィッシングを報告する
不審なドメインを当社の脅威データベースに報告してください — コミュニティを守りましょう
レポートリアルタイム脅威情報フィード
最近のフィッシングレポートと観察された可用性の変化
監視最新情報を入手し、安全を確保しましょう
リアルタイムの脅威を監視するか、誤検知だと思われる場合はこのリストに異議を申し立ててください