amlwiki[.]xyz
“AML WIKI - Crypto AML Check | Enterprise Blockchain Compliance & Risk Assessment”
증거 요약
This domain, amlwiki.xyz, presents a targeted phishing threat designed to harvest credentials and sensitive data from users in the cryptocurrency and blockchain compliance sectors. The site mimics legitimate Anti-Money Laundering (AML) verification platforms, using the page title 'AML WIKI - Crypto AML Check | Enterprise Blockchain Compliance & Risk Assessment' to deceive enterprise users into submitting login credentials, API keys, or other authentication details. Analysis indicates the site is structured to resemble a professional compliance tool, increasing the likelihood of successful social engineering attacks against employees, compliance officers, or blockchain developers who may be searching for AML solutions or risk assessment tools. The domain specifically targets organizations handling digital assets, where compromised credentials could lead to unauthorized access, financial theft, or data breaches within internal systems. Infrastructure analysis reveals multiple technical indicators supporting the phishing classification. The domain amlwiki.xyz was registered on February 14, 2026, through Name.com, Inc., with an unusually future creation date that may indicate domain spoofing or incorrect WHOIS data. It currently resolves to the IP address 35.157.26.135 and uses a Let's Encrypt SSL certificate, providing a false sense of security to visitors. Despite the use of encryption, only 1 out of 95 security vendors on VirusTotal have flagged the domain as malicious, suggesting either recent deployment or evasion techniques. No entries were found on major blocklists at the time of analysis, and the domain remains active, continuing to serve phishing content without interruption. Users who have visited amlwiki.xyz or entered credentials on the site should assume compromise and take immediate remediation steps. All submitted credentials, including usernames, passwords, and API keys, must be considered exposed and should be rotated across all platforms where they were reused. Organizations should conduct a review of internal systems for unauthorized access or anomalous activity, particularly in environments related to cryptocurrency wallets, compliance dashboards, or blockchain infrastructure. Browser sessions should be cleared, and any downloaded files or scripts from the domain should be deleted without execution. Network administrators are advised to block the domain and its resolving IP (35.157.26.135) at the perimeter to prevent further exposure. Security teams should monitor for phishing-related indicators of compromise, including unexpected login attempts or changes in account permissions, and consider implementing additional authentication controls for high-risk systems.
제출된 증거 스냅샷
- 전송됨
- 원장 기록
- 1
- 사건 ID
PD-20260629-DE73C0- 캡처된 페이지 제목
- AML WIKI - Crypto AML Check | Enterprise Blockchain Compliance & Risk Assessment
- PDF 자료
- PDF 증거
증거 전문
Illegal Activities: Active phishing operation targeting victims
Fraud & Deception: Impersonation of legitimate services
Identity Theft: Collection of credentials under false pretenses
Applicable Laws (US):
18 U.S.C. § 1343 - Wire Fraud
18 U.S.C. § 1030 - Computer Fraud and Abuse Act (CFAA)
15 U.S.C. § 45 - FTC Act (Deceptive Practices)
Federal laws prohibit wire fraud, computer fraud, and deceptive business practices.
Action Required: This evidence-backed report demonstrates clear violations requiring suspension per your policies. Continued hosting exposes your organization to regulatory scrutiny and potential legal liability.
Data Coverage
위협 대응 Pipeline
차단 목록 범위
모니터링 중인 외부 피드 10개 · 저장된 스냅샷 2026년 8월 12일
저장된 캡처
도메인 인텔리전스
기술 세부 정보DNS, TLS 이름 및 타임스탬프
ICANN OVERSIGHT
인증 및 RAA 상황
인증 및 RAA 상황
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
기술
신뢰도가 높은 기술 2개 식별
VirusTotal 분석
사이트 성능 분석
Google PageSpeed Insights — mobile performance audit of amlwiki.xyz · checked Jun 29, 2026
이 사이트로 인해 영향을 받으셨나요?
계정 자격 증명, 개인 정보 또는 결제 정보를 입력했거나 이 도메인에서 파일을 다운로드한 경우 즉시 조치를 취하세요. 다음은 사건을 신고하고 자신을 보호하는 데 도움이 되는 리소스입니다.
지역 당국에 신고하십시오
공식 사이버 범죄 연락처 또는 불만사항 초안 작성 →를 받으려면 국가를 선택하세요.
모든 도메인 확인
저장된 차단 목록, WHOIS, DNS 및 공개 스캔 증거를 사용한 위협 분석
지금 스캔하기피싱 신고
의심스러운 도메인을 당사의 위협 데이터베이스에 신고해 주세요 — 커뮤니티를 보호해 주세요
보고서실시간 위협 정보
최근 피싱 보고서 및 관찰된 가용성 변경 사항
모니터링