aml-eth[.]xyz
“AMLeth — #1 Ethereum AML Checker”
aml-eth.xyz — 内容不可用. 品牌冒充:Ethereum; 诈骗类型:Aml Scam. 证据摘要: VirusTotal 6/91 (alphaMountain.ai, CRDF, Forcepoint ThreatSeeker, Gridinsoft, Kaspersky); 3 external blocklist matches (MetaMask, ScamSniffer, SEAL); PhishDestroy score 74/100. 注册商: Spaceship.
为保留原始取证记录,下方的 PhishDestroy AI 详细分析仍使用英文。
Analysis of aml-eth.xyz as of 29 July 2026 shows the domain is actively used for generic phishing. The domain was registered on 9 July 2026 through Spaceship, Inc. and is hosted on the IP address 186.2.175.35. Authoritative name servers are launch1.spaceship.net and launch2.spaceship.net, indicating the registrar’s own DNS infrastructure. The domain appears on a single security blocklist and is currently listed as blocked by the PhishDestroy feed.
VirusTotal scans have recorded detections from 2 of 91 security vendors, confirming that at least a minority of scanners consider the site malicious. No additional public reputation services, such as Google Safe Browsing, have been reported, and no Open Threat Exchange (OTX) pulse or similar indicator is presently associated with the domain. SSL/TLS details, HTTP response codes, and page title information have not been published, leaving the surface‑web characteristics unverified. The combination of recent creation, registrar‑controlled name servers, and early detection by multiple vendors suggests a purpose‑built phishing infrastructure rather than a compromised legitimate site.
Defenders should treat the domain as high‑risk: block the FQDN and its resolved IP at perimeter firewalls, proxy filters, and endpoint allow‑lists; add the domain to internal threat‑intel feeds; and monitor for any future DNS or certificate changes. Continuous re‑scanning with multi‑engine services is recommended to capture additional detections that may emerge as the campaign evolves. Because the site’s content and SSL configuration are not yet publicly documented, analysts should consider manual collection of HTTP headers and page metadata if safe browsing is required.
威胁响应 Pipeline
公共封禁名单状态
已保存的截图
域名情报
技术细节DNS、SSL SAN、时间戳
ICANN OVERSIGHT
认证和 RAA 背景
认证和 RAA 背景
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
所用技术 · 1 identified
DDoS-Guard is a Russian Internet infrastructure company which provides DDoS protection, content delivery network services, and web hosting services.
ddos-guard.net 置信度 100%VirusTotal 分析
存档证据
网站性能分析
Google PageSpeed Insights — mobile performance audit of aml-eth.xyz · checked Jul 29, 2026
证据与外部报告
PD-20260729-C455F6 Recipient: abuse@spaceship.com 您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。