amlprovider[.]ink
“AMLBot - Crypto Compliance & Risk Management”
Зведення доказів
Analysis of the domain amlprovider.ink indicates it was actively impersonating AMLBot, a crypto compliance and risk management platform, as of July 2026. The domain resolved to the IP address 18.208.88.157, hosted on Amazon Web Services (AS14618) in the United States. Its SSL certificate was issued under the E5 root, a detail that alone does not confirm malicious intent but is consistent with infrastructure used in phishing campaigns. The page title, 'AMLBot - Crypto Compliance & Risk Management,' directly matches the branding of the legitimate service, suggesting an intent to deceive users seeking AMLBot’s tools. The domain was registered on February 21, 2026, and was taken offline prior to this report.
At the time of assessment, it appeared on one security blocklist, though no active detections were recorded across 93 vendors in VirusTotal scans. The absence of detections does not confirm safety, as phishing domains often evade initial scans or operate undetected for brief periods. Infrastructure analysis reveals the domain was flagged by PhishDestroy, a specialized anti-phishing service, further supporting its classification as a crypto scam. Defenders should treat amlprovider.ink as a confirmed brand impersonation threat targeting AMLBot’s user base.
While the domain is currently offline, its infrastructure and registration timeline align with short-lived phishing operations. Organizations should monitor for re-registration under similar naming conventions or shifts to new IPs within the same hosting provider. No evidence suggests this domain was part of a broader campaign, but the use of AWS infrastructure is common in phishing operations due to its scalability and transient IP availability. The exact content and functionality of the site remain unanalyzed, limiting further technical assessment.
Data Coverage
Процес реагування на загрози Pipeline
Перевірка за блок-листами
10 зовнішніх джерел під наглядом · знімок від 10.08.2026
Аналіз VirusTotal
Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога