check[.]aml-kyt[.]icu
“Check AML Online - AML проверка онлайн”
check.aml-kyt.icu — Неперевірений. Тип шахрайства: Crypto Scam. Зведення доказів: VirusTotal 4/91 (Chong Lua Dao, Forcepoint ThreatSeeker, Fortinet, Gridinsoft); Spamhaus DBL_PHISH; PhishDestroy score 67/100. Реєстратор: Web Commerce Communica….
Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.
Analysis of the domain check.aml-kyt.icu shows a newly registered site (creation date August 01 2025) that was hosted on Cloudflare infrastructure and resolved to IP 172.67.169.238, an address attributed to AS13335 Cloudflare, Inc. in the United States. The domain is configured with Cloudflare nameservers (bob.ns.cloudflare.com, candy.ns.cloudflare.com) and was registered through Web Commerce Communications Limited. No TLS certificate was observed, indicating the site was served over plain HTTP, which is atypical for a service purporting to perform AML checks. The page title returned by the site – “Check AML Online – AML проверка онлайн” – suggests a focus on anti‑money‑laundering verification, yet the threat classification lists the activity as a crypto‑related scam.
Trust metrics are extremely low: Gridinsoft assigns a score of 0 / 100, while Scamadviser rates the domain at 1 / 100, both reflecting a high probability of malicious intent. VirusTotal scans recorded four detections out of ninety‑five security vendors, reinforcing the suspicion of abuse. The domain appears on a single external blocklist and has been actively blocked by PhishDestroy.
Current HTTP status is offline, but the combination of poor trust scores, lack of encryption, and vendor detections provides sufficient evidence for defenders to treat the indicator as hostile. Uncertainty remains regarding the exact payload or phishing lures used, as no page content beyond the title has been disclosed. Recommendations include immediate blocking of the domain and its associated IP, inclusion in internal threat‑intel feeds, monitoring of the DNS records for potential re‑use, and continued observation of related Cloudflare‑hosted infrastructure for similar patterns.
Сигнали безпеки
Процес реагування на загрози Pipeline
Статус у публічних блоклистах
Збережений знімок
Аналітика доменів
Технічні деталіDNS, SAN-адреси SSL, мітки часу
ЗОНА SHORTDOT · ПУБЛІЧНІ ДОКАЗИ
.icu
ShortDot zone evidence
ShortDot zone evidence
The linked repository preserves daily zone observations across seven ShortDot-operated TLDs, including registration volume and abuse-related indicators. This registry context is supporting background and is not an independent detection for the domain in this report.
ICANN OVERSIGHT
Registration: aml-kyt.icu
Акредитація та контекст RAA
Акредитація та контекст RAA
Registrar accreditation and DNS abuse obligations
For the registrable domain aml-kyt.icu behind this subdomain, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Аналіз VirusTotal
Докази та зовнішні звіти
Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога