amlprovider[.]ink
“AMLBot - Crypto Compliance & Risk Management”
Resumo das evidências
Analysis of the domain amlprovider.ink indicates it was actively impersonating AMLBot, a crypto compliance and risk management platform, as of July 2026. The domain resolved to the IP address 18.208.88.157, hosted on Amazon Web Services (AS14618) in the United States. Its SSL certificate was issued under the E5 root, a detail that alone does not confirm malicious intent but is consistent with infrastructure used in phishing campaigns. The page title, 'AMLBot - Crypto Compliance & Risk Management,' directly matches the branding of the legitimate service, suggesting an intent to deceive users seeking AMLBot’s tools. The domain was registered on February 21, 2026, and was taken offline prior to this report.
At the time of assessment, it appeared on one security blocklist, though no active detections were recorded across 93 vendors in VirusTotal scans. The absence of detections does not confirm safety, as phishing domains often evade initial scans or operate undetected for brief periods. Infrastructure analysis reveals the domain was flagged by PhishDestroy, a specialized anti-phishing service, further supporting its classification as a crypto scam. Defenders should treat amlprovider.ink as a confirmed brand impersonation threat targeting AMLBot’s user base.
While the domain is currently offline, its infrastructure and registration timeline align with short-lived phishing operations. Organizations should monitor for re-registration under similar naming conventions or shifts to new IPs within the same hosting provider. No evidence suggests this domain was part of a broader campaign, but the use of AWS infrastructure is common in phishing operations due to its scalability and transient IP availability. The exact content and functionality of the site remain unanalyzed, limiting further technical assessment.
Data Coverage
Pipeline de resposta a ameaças
Cobertura de listas de bloqueio
10 fontes externas monitoradas · instantâneo de 13/08/2026
10 fontes externas monitoradas Sem correspondência
Análise do VirusTotal
Você foi afetado por este site?
Se você inseriu credenciais de conta, informações pessoais ou de pagamento, ou baixou um arquivo deste domínio, tome medidas imediatas. Abaixo estão os recursos para ajudá-lo a relatar o incidente e se proteger.
Notifique as autoridades locais
Selecione seu país para obter contactos oficiais do cibercrime ou crie um rascunho de reclamação →.
Verificar qualquer domínio
Análise de ameaças usando lista de bloqueio armazenada, WHOIS, DNS e evidências de verificação pública
Digitalize agoraDenunciar phishing
Envie domínios suspeitos para nosso banco de dados de ameaças — proteja a comunidade
DenunciarFeed de ameaças em tempo real
Relatórios recentes de phishing e alterações de disponibilidade observadas
MonitorarMantenha-se informado, mantenha-se seguro
Monitore ameaças em tempo real ou conteste esta listagem caso acredite que se trate de um falso positivo