amlweb3[.]ink
“AMLBot - Crypto Compliance & Risk Management”
Resumo das evidências
On 24 July 2026, the domain amlweb3.ink was observed supporting a brand‑impersonation campaign targeting AMLBot. The domain was registered on 21 February 2026 and subsequently resolved to the IPv4 address 63.176.8.218, which belongs to Amazon.com, Inc. (AS16509) and is geolocated in Germany. The hosting provider is Amazon Web Services, indicating use of cloud infrastructure typical for rapid deployment. The site presented the page title “AMLBot – Crypto Compliance & Risk Management,” matching the targeted brand and confirming the intent to masquerade as an official AMLBot service. SSL analysis identified a certificate labeled “E6,” confirming that the site employed TLS encryption, but the certificate does not mitigate the underlying malicious purpose.
Reputation checks show the domain appears on two independent blocklists, specifically PhishDestroy and ScamSniffer, both of which have flagged the site as malicious. VirusTotal scans recorded two positive detections out of ninety‑three submitted security engines, reinforcing the classification as a crypto‑related scam. The campaign is currently listed as offline, suggesting the infrastructure has been taken down or is temporarily inaccessible. Defenders should continue to enforce deny‑list rules for both the domain and its resolved IP address, given the association with known blocklists and the positive VirusTotal detections.
Monitoring of Amazon‑hosted IP ranges for similar fast‑flux patterns is recommended, as is the inclusion of the observed page title in content‑based detection signatures. Because the site leverages legitimate TLS, network‑level inspection of encrypted traffic may be required to identify subsequent re‑hosted iterations. Awareness‑raising messages to users of AMLBot services should reference the exact page title to aid in distinguishing authentic communications from counterfeit pages.
Data Coverage
Pipeline de resposta a ameaças
Cobertura de listas de bloqueio
10 fontes externas monitoradas · instantâneo de 11/08/2026
9 fontes externas monitoradas Sem correspondência
Análise do VirusTotal
Você foi afetado por este site?
Se você inseriu credenciais de conta, informações pessoais ou de pagamento, ou baixou um arquivo deste domínio, tome medidas imediatas. Abaixo estão os recursos para ajudá-lo a relatar o incidente e se proteger.
Notifique as autoridades locais
Selecione seu país para obter contactos oficiais do cibercrime ou crie um rascunho de reclamação →.
Verificar qualquer domínio
Análise de ameaças usando lista de bloqueio armazenada, WHOIS, DNS e evidências de verificação pública
Digitalize agoraDenunciar phishing
Envie domínios suspeitos para nosso banco de dados de ameaças — proteja a comunidade
DenunciarFeed de ameaças em tempo real
Relatórios recentes de phishing e alterações de disponibilidade observadas
MonitorarMantenha-se informado, mantenha-se seguro
Monitore ameaças em tempo real ou conteste esta listagem caso acredite que se trate de um falso positivo