amlrobotcheck[.]com
Verificação de phishing e segurança de amlrobotcheck.com
“AMLBot - The full-fledged crypto compliance solution”
amlrobotcheck.com — Último ativo conhecido (HTTP 200). Representação da marca: AMLBot; Tipo de golpe: Aml Scam. Resumo das evidências: VirusTotal 2/93 (Ermes, Gridinsoft); 1 external blocklist match (ScamSniffer); PhishDestroy score 68/100. Registrador: PDR.
A análise detalhada do PhishDestroy AI permanece em inglês para preservar o registro forense original.
On 24 July 2026, the domain amlrobotcheck.com was observed serving HTTP 200 responses before being taken offline. The site presented the page title “AMLBot - The full-fledged crypto compliance solution”, directly referencing the AMLBot brand and indicating an investment‑scam motive. Registration data shows the domain was created on 21 February 2026 through PDR Ltd. d/b/a PublicDomainRegistry.com and uses four RegWay nameservers (dns1–dns4.regway.com). No TLS certificate was deployed, leaving the site accessible only via plain HTTP. DNS resolution points to IP 193.58.121.240, which belongs to AS215439 PLAY2GO INTERNATIONAL LIMITED and is geolocated in Germany.
The hosting infrastructure does not appear to be shared with known legitimate AMLBot services. Multiple threat‑intelligence feeds have flagged the domain. Two of ninety‑three VirusTotal scanners raised detections, and the domain appears on two public blocklists, specifically PhishDestroy and ScamSniffer, which have categorized it as an investment‑scam impersonating AMLBot. No additional evidence such as Safe Browsing or OTX entries were recorded at the time of analysis. The absence of an SSL certificate, combined with the brand‑specific page title and the rapid registration-to‑take‑down timeline, suggests a short‑lived abuse campaign designed to harvest credentials or solicit funds from entities seeking crypto‑compliance solutions.
Uncertainty remains regarding the exact payload delivered to visitors, as the site content has not been archived. Analysts should treat any URLs or emails referencing amlrobotcheck.com as hostile, block the domain at perimeter defenses, and monitor the associated IP address for future activity. Continuous re‑query of reputation services is advised to capture any re‑use of the infrastructure. Organizations using AMLBot services should verify that no credential changes have occurred and consider implementing multi‑factor authentication for their compliance portals.
Pipeline de resposta a ameaças
Status da lista de bloqueios pública
Captura armazenada
Inteligência de Domínios
Detalhes técnicosDNS, SANs do SSL, carimbos de data e hora
ICANN OVERSIGHT
Credenciamento e contexto RAA
Credenciamento e contexto RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Análise do VirusTotal
Evidências e relatórios externos
Você foi afetado por este site?
Se você inseriu credenciais de conta, informações pessoais ou de pagamento, ou baixou um arquivo deste domínio, tome medidas imediatas. Abaixo estão os recursos para ajudá-lo a relatar o incidente e se proteger.
Notifique as autoridades locais
Selecione seu país para obter contactos oficiais do cibercrime ou crie um rascunho de reclamação →.
Verificar qualquer domínio
Análise de ameaças usando lista de bloqueio armazenada, WHOIS, DNS e evidências de verificação pública
Digitalize agoraDenunciar phishing
Envie domínios suspeitos para nosso banco de dados de ameaças — proteja a comunidade
DenunciarFeed de ameaças em tempo real
Relatórios recentes de phishing e alterações de disponibilidade observadas
MonitorarMantenha-se informado, mantenha-se seguro
Monitore ameaças em tempo real ou conteste esta listagem caso acredite que se trate de um falso positivo