amlgate[.]org
Verificação de phishing e segurança de amlgate.org
“Nur einen Moment…”
amlgate.org — Conteúdo indisponível (HTTP 502). Tipo de golpe: Crypto Scam. Resumo das evidências: VirusTotal 1/95 (Gridinsoft); PhishDestroy score 55/100. Registrador: PDR.
A análise detalhada do PhishDestroy AI permanece em inglês para preservar o registro forense original.
amlgate.org was registered on 16 May 2025 through PublicDomainRegistry.com (PDR Ltd.). The authoritative nameservers are ns1.suspended-domain.com and ns2.suspended-domain.com, both commonly associated with domains that have been taken offline or are in a holding state. DNS resolution points to the IPv6 address 2606:4700:3037::ac43:856b, which belongs to Cloudflare, Inc. (AS13335) and is geolocated to the United States. No TLS certificate is presented for the host, indicating that the site was served over plain HTTP when it was accessible.
The only visible page element captured is the title “Nur einen Moment…”, a German phrase meaning “Just a moment…”, which is frequently used by malicious actors to delay users while background scripts execute. The domain is listed on a single security blocklist and has been flagged by PhishDestroy. VirusTotal scans show one out of ninety‑five security vendors marked the domain as malicious, reinforcing the suspicion raised by other indicators. The threat classification recorded is a “Crypto Scam”, suggesting that the site was intended to lure victims into cryptocurrency‑related fraud, although the specific payload or wallet addresses have not been publicly disclosed.
Because the site is currently offline, active exploitation cannot be observed, but the infrastructure choices—new registration, suspended‑domain nameservers, Cloudflare hosting, and lack of encryption—are consistent with typical phishing and cryptocurrency‑drain campaigns. Defenders should add amlgate.org to deny‑list rules, monitor for other domains using the same nameserver pair or the same Cloudflare IPv6 prefix, and consider expanding detection to similar German‑language title patterns. Continuous observation of the registrar’s newly created domains may also reveal future threats that reuse this hosting configuration.
Pipeline de resposta a ameaças
Status da lista de bloqueios pública
Captura armazenada
Inteligência de Domínios
Detalhes técnicosDNS, SANs do SSL, carimbos de data e hora
ICANN OVERSIGHT
Credenciamento e contexto RAA
Credenciamento e contexto RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Inteligência forense
Análise do VirusTotal
Evidências e relatórios externos
Você foi afetado por este site?
Se você inseriu credenciais de conta, informações pessoais ou de pagamento, ou baixou um arquivo deste domínio, tome medidas imediatas. Abaixo estão os recursos para ajudá-lo a relatar o incidente e se proteger.
Notifique as autoridades locais
Selecione seu país para obter contactos oficiais do cibercrime ou crie um rascunho de reclamação →.
Verificar qualquer domínio
Análise de ameaças usando lista de bloqueio armazenada, WHOIS, DNS e evidências de verificação pública
Digitalize agoraDenunciar phishing
Envie domínios suspeitos para nosso banco de dados de ameaças — proteja a comunidade
DenunciarFeed de ameaças em tempo real
Relatórios recentes de phishing e alterações de disponibilidade observadas
MonitorarMantenha-se informado, mantenha-se seguro
Monitore ameaças em tempo real ou conteste esta listagem caso acredite que se trate de um falso positivo