digital[.]crypto-connectweb3[.]com
“AMLBot”
Сводка доказательств
Analysis indicates that the domain digital.crypto-connectweb3.com was actively impersonating AMLBot, a cryptocurrency compliance service, as of its registration on February 21, 2026. The domain was hosted on infrastructure associated with Namecheap, Inc. (AS22612), resolving to the IP address 209.74.76.6, located in Great Britain. No SSL certificate was detected, increasing the risk of interception or manipulation of user data. The page title explicitly matched the targeted brand, 'AMLBot,' confirming the intent to deceive users into believing they were interacting with the legitimate service.
At the time of assessment, the domain was flagged by two of the 93 security vendors on VirusTotal and appeared on three independent security blocklists, including PhishDestroy, MetaMask, and SEAL, which classify it as malicious infrastructure. The domain was registered through Spaceship, Inc., with nameservers launch1.spaceship.net and launch2.spaceship.net, further linking it to known phishing-enabling providers. As of July 25, 2026, the domain has been taken offline, though its prior activity and infrastructure remain relevant for historical threat tracking.
Defenders are advised to block the domain, its resolved IP, and associated nameservers at the network level. Security teams should review logs for connections to 209.74.76.6 or requests to digital.crypto-connectweb3.com, particularly from users who may have engaged with cryptocurrency-related services. While the domain is no longer active, its registration details and hosting history provide actionable indicators for detecting similar phishing campaigns targeting AMLBot or other crypto compliance platforms.
Снимок отправленных доказательств
- Отправлено
- Записи журнала
- 1
- ID дела
PD-20260218-9AFC61- Заголовок сохранённой страницы
- AMLBot
- PDF-файл
- PDF с доказательствами
Полный текст доказательств
Acceptable Use Policy (AUP): The domain digital.crypto-connectweb3.com is engaged in phishing activities, which are strictly prohibited under your AUP. This domain is designed to deceive users into providing sensitive personal information.
Terms of Service (TOS): The continued operation of this domain constitutes a violation of your TOS, which reserves the right to suspend or terminate services for any activities deemed illegal or fraudulent.
Applicable Laws (IS):
Act on Electronic Communications (No. 81/2003): This law prohibits the use of electronic communications for fraudulent purposes, including phishing.
Criminal Code of Iceland (No. 19/1940): Under this code, phishing activities can be prosecuted as fraud, which carries significant penalties.
Regulatory Note: Failure to take immediate action against this domain may result in regulatory scrutiny and potential liability under applicable laws. Non-compliance could expose your organization to legal repercussions.
Data Coverage
Данные сетевой безопасности
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| OpenDNS | digital.crypto-connectweb3.com |
phishing | Phishing Block |
| Hagezi Threat Feed | digital.crypto-connectweb3.com |
malicious | Sinkholed |
| DNS4EU | digital.crypto-connectweb3.com |
malicious | Sinkholed |
Процесс реагирования на угрозы
Проверка по блок-листам
10 внешних источников под наблюдением · снимок от 10.08.2026
8 внешних источников под наблюдением Совпадений нет
Хронология обнаружения
-
Cloudflare Radar
Сканирование Cloudflare Radar сохранено · Открыть сканирование
Сохранённый снимок
Аналитика доменов
Технические деталиDNS, имена TLS и временные метки
ICANN OVERSIGHT
Registration: crypto-connectweb3.com
Аккредитация и контекст RAA
Аккредитация и контекст RAA
Registrar accreditation and DNS abuse obligations
For the registrable domain crypto-connectweb3.com behind this subdomain, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Анализ VirusTotal
Повлиял ли на вас этот сайт?
Если вы ввели учетные данные, личную или платежную информацию или загрузили файл с этого домена, примите немедленные меры. Ниже приведены ресурсы, которые помогут вам сообщить об инциденте и защитить себя.
Сообщите об этом в местные органы власти
Выберите свою страну, чтобы получить официальные контакты по киберпреступности или создать проект жалобы →.
Проверить любой домен
Анализ угроз с использованием сохраненного черного списка, WHOIS, DNS и общедоступных доказательств сканирования.
Сканировать сейчасСообщить о фишинге
Добавляйте подозрительные домены в нашу базу данных угроз — защищайте сообщество
СообщитьПоток оперативных данных об угрозах
Недавние сообщения о фишинге и наблюдаемые изменения доступности
ОтслеживатьБудьте в курсе событий, берегите себя
Отслеживайте актуальные угрозы или оспорьте эту запись, если считаете, что это ложное срабатывание