MALICIOUS — HIGH
aml-trn[.]com
Analysis of the domain aml-trn.com indicates it was actively involved in a wallet and seed phishing campaign targeting users of the cryptocurrency exchange Bitget.
- VirusTotal
- 2/95
- Blocklists
- No stored match
- Доступность
- Контент недоступен · HTTP 502
Do not enter credentials, seed phrases, payment details, or personal information on this domain.
Jump to section
aml-trn.com — Контент недоступен (HTTP 502). Олицетворение бренда: Bitget; Тип мошенничества: Wallet/seed Phishing. Сводка доказательств: VirusTotal 2/95 (alphaMountain.ai, Fortinet); PhishDestroy score 56/100. Регистратор: Web Commerce Communica….
Подробный анализ PhishDestroy AI ниже оставлен на английском, чтобы сохранить исходную криминалистическую запись.
Evidence Analysis
Analysis of the domain aml-trn.com indicates it was actively involved in a wallet and seed phishing campaign targeting users of the cryptocurrency exchange Bitget. The domain was registered on May 29, 2025, through Web Commerce Communications Limited and resolved to the IP address 104.21.56.176, hosted on Cloudflare's network (AS13335). Infrastructure analysis reveals the use of Cloudflare nameservers (DONNA.NS.CLOUDFLARE.COM and NASH.NS.CLOUDFLARE.COM), a common tactic to obscure hosting origins and evade takedowns. No SSL certificate was detected, increasing the likelihood of interception or manipulation of user data in transit. The page title, 'AML Check,' suggests the site impersonated a Know Your Customer (KYC) or Anti-Money Laundering (AML) verification process, a technique frequently employed to harvest wallet seeds or credentials under the guise of compliance.
The domain was flagged by one security blocklist and identified by PhishDestroy as part of a wallet/seed phishing operation. As of July 22, 2026, the domain is offline, though its prior activity and infrastructure remain relevant for retrospective detection. Two of 95 security vendors on VirusTotal flagged the domain as malicious, providing additional corroboration of its harmful intent. Defenders should treat this domain as a confirmed threat vector for cryptocurrency-related phishing.
Indicators of compromise (IOCs) include the domain name, IP address 104.21.56.176, and the 'AML Check' page title. Network security teams are advised to block or monitor traffic to this domain and its associated IP, particularly in environments where Bitget or similar platforms are used. Given the domain's use of Cloudflare, further investigation into related infrastructure may uncover additional malicious assets. The absence of an SSL certificate and the domain's presence on a security blocklist further justify its classification as a high-risk artifact, even in its current offline state.
Охват данных12 recorded checks
Процесс реагирования на угрозы
Статус в публичных блок-листах
Сохранённый снимок
Аналитика доменов
Технические сведенияDNS, SAN в протоколе SSL, временные метки
ICANN OVERSIGHT
Аккредитация и контекст RAA
Аккредитация и контекст RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Анализ VirusTotal
Доказательства и внешние отчетыIndependent lookups and source reports
Victim safety and official reportingImmediate actions and verified reporting channels
Если вы ввели учетные данные, личную или платежную информацию или загрузили файл с этого домена, примите немедленные меры. Ниже приведены ресурсы, которые помогут вам сообщить об инциденте и защитить себя.
Сообщите об этом в местные органы власти
Выберите свою страну, чтобы получить официальные контакты по киберпреступности или создать проект жалобы →.