aml-alabama[.]com
“AMLCheck - Secure Crypto Transaction Monitoring”
证据摘要
Analysis of the domain aml-alabama.com indicates it was actively involved in an investment scam, classified as phishing with an elevated risk level. The domain was registered on September 13, 2025, through PDR Ltd. d/b/a PublicDomainRegistry.com and resolved to the IP address 50.6.193.23, hosted on AS19871 (Network Solutions, LLC) in the United States. Infrastructure analysis reveals the use of Google Cloud, Google Cloud CDN, Cloudflare, and HTTP/3, alongside nameservers dns1.regway.com through dns4.regway.com. The SSL certificate was issued by Google Trust Services (WE1), a common choice for both legitimate and malicious domains.
The page title, 'AMLCheck - Secure Crypto Transaction Monitoring,' suggests a focus on cryptocurrency-related fraud, aligning with the scam type identified in threat intelligence. The domain appears on one security blocklist and was flagged by two of 95 security vendors on VirusTotal, though the specific detection context remains unclear. PhishDestroy blocked access to the domain, which is now offline as of the report date. The combination of Cloudflare and Google Cloud infrastructure is frequently observed in phishing campaigns due to its low cost and perceived legitimacy.
Defenders should treat this domain as confirmed malicious, particularly in environments handling cryptocurrency transactions or financial services. The registration details and hosting provider do not indicate any affiliation with legitimate AML (Anti-Money Laundering) services. No evidence suggests the domain was part of a larger campaign or kit, though the use of regway.com nameservers may warrant further investigation for related activity. Network-level blocking of 50.6.193.23 and monitoring for regway.com-associated domains is recommended for proactive defense.
Data Coverage
威胁响应 Pipeline
阻止列表覆盖
监控中的外部数据源 10 个 · 已存快照 2026年8月12日
检测时间线
-
域名状态
可访问 → 无法访问
-
Cloudflare Radar
已存储 Cloudflare Radar 扫描 · 打开扫描
-
域名状态
无法访问 → 可访问
已保存的截图
域名情报
技术详情DNS、TLS 名称和时间戳
ICANN OVERSIGHT
认证和 RAA 背景
认证和 RAA 背景
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
VirusTotal 分析
您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。
检查任意域名
使用存储的阻止列表、WHOIS、DNS 和公共扫描证据进行威胁分析
立即扫描举报网络钓鱼
将可疑域名提交至我们的威胁数据库——保护社区
报告实时威胁动态
最近的网络钓鱼报告和观察到的可用性变化
监控