scan-aml[.]info
scan-aml.info 피싱 및 보안 점검
“Scann AML”
scan-aml.info — 서버 오류 (HTTP 502). 브랜드 사칭: Csgo; 사기 유형: Crypto Scam. 증거 요약: VirusTotal 3/91 (alphaMountain.ai, CRDF, Gridinsoft); URLQuery 100 det.; URLScan malicious verdict; PhishDestroy score 95/100.
원본 포렌식 기록을 보존하기 위해 아래의 상세 PhishDestroy AI 분석은 영어로 유지됩니다.
scan-aml.info was observed resolving to the Cloudflare IP address 104.26.15.158, which is hosted in the United States under ASN 13335 (Cloudflare, Inc.). The domain is served by the Cloudflare name servers lindsey.ns.cloudflare.com and rayden.ns.cloudflare.com and does not present an SSL/TLS certificate, indicating that HTTPS was not configured at the time of observation. Public reputation checks show the domain appearing on a single security blocklist and being flagged by PhishDestroy, confirming that it is recognized as malicious by at least one dedicated anti‑phishing feed. VirusTotal analysis recorded 2 detections out of 95 scanning engines, suggesting limited but non‑trivial vendor consensus on the threat. The page title returned by HTTP requests is “Scann AML”, which does not directly reference the impersonated brand.
Gridinsoft’s trust score for the domain is 0 out of 100, the lowest possible rating, reinforcing the suspicion of malicious intent. The domain is explicitly listed as impersonating the “csgo” brand, a shorthand for Counter‑Strike: Global Offensive, and is classified as a crypto‑scam in the available intelligence. No further detail about the payload, payment mechanisms, or victim interaction flow has been disclosed, and the site was taken offline before a deeper content analysis could be performed. Consequently, the exact nature of the scam page, such as whether it hosted a phishing form, a cryptocurrency address, or a malicious download, remains unknown.
Defenders should block DNS resolution for scan-aml.info at the network perimeter and add the associated IP address 104.26.15.158 to any existing Cloudflare‑origin blocklists. Because the domain leverages Cloudflare’s infrastructure, additional scrutiny of other domains sharing the same IP may be warranted. Monitoring for re‑registration of the domain or the appearance of similar sub‑domains on the same name servers should be incorporated into threat‑intel feeds.
위협 대응 Pipeline
공개 차단 목록 상태
VirusTotal 분석
증거 및 외부 보고서
이 사이트로 인해 영향을 받으셨나요?
계정 자격 증명, 개인 정보 또는 결제 정보를 입력했거나 이 도메인에서 파일을 다운로드한 경우 즉시 조치를 취하세요. 다음은 사건을 신고하고 자신을 보호하는 데 도움이 되는 리소스입니다.
지역 당국에 신고하십시오
공식 사이버 범죄 연락처 또는 불만사항 초안 작성 →를 받으려면 국가를 선택하세요.