amlsecure[.]report
Проверка домена amlsecure.report на фишинг и безопасность
“The Best AML Service for Your Business - AML Secure”
amlsecure.report — Контент недоступен (HTTP 502). Тип мошенничества: Crypto Scam. Сводка доказательств: VirusTotal 3/91 (CRDF, Gridinsoft, SOCRadar); 4 external blocklist matches; PhishDestroy score 82/100. Регистратор: Global Domain Group.
Подробный анализ PhishDestroy AI ниже оставлен на английском, чтобы сохранить исходную криминалистическую запись.
Analysis of amlsecure.report indicates that the domain is being used for credential phishing, specifically targeting users of anti‑money‑laundering services. The site was created on 14 December 2025 and is currently taken offline, but historical evidence shows it was actively serving malicious content. The page title observed during its active period was "The Best AML Service for Your Business - AML Secure," suggesting an attempt to lure victims with a legitimate‑sounding offering. The domain resolves to IP address 188.114.97.3, which is hosted by Cloudflare (AS13335) in the United States.
No SSL certificate was presented, leaving the connection unencrypted and making the site easier to intercept or tamper with. Reputation data is extremely poor: Gridinsoft assigns a trust score of 0 out of 100, and the domain appears on five security blocklists. Detection services have flagged the domain, with two of ninety‑five VirusTotal scanners raising alerts, and it is explicitly blocked by PhishDestroy, ScamSniffer, Polkadot, Enkrypt, and Codeesura. The registrar listed is Global Domain Group LLC, and the authoritative nameservers are augustus.ns.cloudflare.com and eve.ns.cloudflare.com.
While the exact phishing payload and credential collection mechanisms have not been captured, the combination of a targeted page title, lack of TLS, low trust rating, and multiple blocklist entries strongly indicates a credential‑phishing operation. Defenders should add amlsecure.report to firewall and proxy block lists, monitor DNS queries for the domain and its associated IP, and enforce TLS inspection policies to detect any future attempts to host similar content. Continuous observation of the Cloudflare IP range for related activity is advised, as threat actors may shift to new subdomains under the same hosting infrastructure.
Процесс реагирования на угрозы
Статус в публичных блок-листах
Сохранённый снимок
Аналитика доменов
Технические сведенияDNS, SAN в протоколе SSL, временные метки
ICANN OVERSIGHT
Аккредитация и контекст RAA
Аккредитация и контекст RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Анализ VirusTotal
Доказательства и внешние отчеты
Повлиял ли на вас этот сайт?
Если вы ввели учетные данные, личную или платежную информацию или загрузили файл с этого домена, примите немедленные меры. Ниже приведены ресурсы, которые помогут вам сообщить об инциденте и защитить себя.
Сообщите об этом в местные органы власти
Выберите свою страну, чтобы получить официальные контакты по киберпреступности или создать проект жалобы →.
Проверить любой домен
Анализ угроз с использованием сохраненного черного списка, WHOIS, DNS и общедоступных доказательств сканирования.
Сканировать сейчасСообщить о фишинге
Добавляйте подозрительные домены в нашу базу данных угроз — защищайте сообщество
СообщитьПоток оперативных данных об угрозах
Недавние сообщения о фишинге и наблюдаемые изменения доступности
ОтслеживатьБудьте в курсе событий, берегите себя
Отслеживайте актуальные угрозы или оспорьте эту запись, если считаете, что это ложное срабатывание