Notification and current-status evidence
The sent-report ledger records the first outgoing report at .
The recorded recipient is abuse@dynadot.com.
The latest stored availability evidence still shows the domain reachable; 5 months has elapsed since the first outgoing report.
ICANN RAA §3.18 describes registrar abuse-contact and handling obligations. This section records outgoing timestamps, listed recipients, case identifiers, and later availability. It does not by itself prove receipt, acknowledgement, investigation, remediation, or contractual non-compliance.
aml-defense[.]one
“AMLBot - Comprehensive Crypto Compliance Solution | Free AML Crypto Check”
aml-defense.one — Não verificado. Tipo de golpe: Aml Scam. Resumo das evidências: VirusTotal 6/93 (ADMINUSLabs, alphaMountain.ai, G-Data, Gridinsoft, SOCRadar); 2 external blocklist matches (MetaMask, SEAL); PhishDestroy score 68/100. Registrador: Dynadot.
A análise detalhada do PhishDestroy AI permanece em inglês para preservar o registro forense original.
The domain aml-defense.one is assessed to pose an elevated risk level, specifically engaging in brand impersonation threats. This domain attempts to mimic legitimate brands associated with AML scams, potentially deceiving users into divulging sensitive information by presenting itself as a credible platform for crypto compliance checks.
Technical analysis of aml-defense.one indicates that it resolves to the IP address 107.189.22.183. According to VirusTotal, this domain is flagged by 6 out of 95 security vendors, suggesting that while it is not universally recognized as malicious, there is significant concern among certain security entities. The domain was registered through Dynadot LLC on February 21, 2026, and utilized an SSL certificate issued by Let's Encrypt, identifiable by E8. Additionally, aml-defense.one has already been listed on 3 security blocklists, further indicating recognition of its potential threat. Despite its current offline status, the initial detection, and subsequent takedown highlight the potential vulnerability it posed to internet users.
Given these findings, it is crucial for users to implement specific mitigation steps to protect themselves from such threats. Individuals should verify the legitimacy of websites claiming to offer financial services by cross-referencing official sources and contacting the brands directly. Further, deploying browser security extensions can enhance users' ability to distinguish between genuine and phishing sites. Organizations should regularly update their security protocols and employee training programs to include identification strategies for brand impersonation tactics. Continuous monitoring of newly registered domains similar to aml-defense.one is also recommended to preemptively detect and respond to emerging threats.
Pipeline de resposta a ameaças
Status da lista de bloqueios pública
Captura armazenada
Inteligência de Domínios
Detalhes técnicosDNS, SANs do SSL, carimbos de data e hora
ICANN OVERSIGHT
Credenciamento e contexto RAA
Credenciamento e contexto RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Tecnologias · 6 identified
JavaScript runtime built on Chrome V8 engine for server-side development.
JavaScript library for building user interfaces with component-based architecture.
High-performance HTTP server and reverse proxy, known for stability and low resource usage.
React framework for production with hybrid static and server rendering.
Module bundler for modern JavaScript applications.
Análise do VirusTotal
Evidências arquivadas
Evidências e relatórios externos
PD-20260220-F9BE64 Recipient: abuse@dynadot.com Você foi afetado por este site?
Se você inseriu credenciais de conta, informações pessoais ou de pagamento, ou baixou um arquivo deste domínio, tome medidas imediatas. Abaixo estão os recursos para ajudá-lo a relatar o incidente e se proteger.
Notifique as autoridades locais
Selecione seu país para obter contactos oficiais do cibercrime ou crie um rascunho de reclamação →.
Verificar qualquer domínio
Análise de ameaças usando lista de bloqueio armazenada, WHOIS, DNS e evidências de verificação pública
Digitalize agoraDenunciar phishing
Envie domínios suspeitos para nosso banco de dados de ameaças — proteja a comunidade
DenunciarFeed de ameaças em tempo real
Relatórios recentes de phishing e alterações de disponibilidade observadas
MonitorarMantenha-se informado, mantenha-se seguro
Monitore ameaças em tempo real ou conteste esta listagem caso acredite que se trate de um falso positivo