Notification and current-status evidence
The sent-report ledger records the first outgoing report at .
The recorded recipient is abuse@dynadot.com.
The latest stored availability evidence still shows the domain reachable; 6 months has elapsed since the first outgoing report.
ICANN RAA §3.18 describes registrar abuse-contact and handling obligations. This section records outgoing timestamps, listed recipients, case identifiers, and later availability. It does not by itself prove receipt, acknowledgement, investigation, remediation, or contractual non-compliance.
amlcheckwallet[.]cc
“AML Check”
amlcheckwallet.cc — 未验证. 品牌冒充:Csgo; 诈骗类型:Crypto Scam. 证据摘要: VirusTotal 9/91 (alphaMountain.ai, Chong Lua Dao, CRDF, CyRadar, Forcepoint ThreatSeeker); URLQuery 100 det.; URLScan malicious verdict; Spamhaus DBL_PHISH; PhishDestroy score 95/100. 注册商: Dynadot.
为保留原始取证记录,下方的 PhishDestroy AI 详细分析仍使用英文。
This domain was registered on February 21 2026 through Dynadot LLC and resolves to the Cloudflare‑owned address 104.21.25.10, which is associated with ASN 13335 in the United States. The site lacks an SSL certificate and currently returns no HTTP response because it has been taken offline. Infrastructure analysis shows the domain is served by Cloudflare name servers (annalise.ns.cloudflare.com, marty.ns.cloudflare.com) and employs DDoS‑Guard technology, a common component of malicious hosting stacks. The page title returned during the brief online window was “AML Check”, and the domain is classified as a crypto‑scam that impersonates the “csgo” brand. Reputation services have placed the domain on three security blocklists, and Gridinsoft assigned a trust score of 0 / 100. Additional protective products, including PhishDestroy, MetaMask, and SEAL, have explicitly blocked the domain. VirusTotal scans indicate that five of ninety‑three security vendors flagged the site, reinforcing the suspicion of malicious intent.
Uncertainty remains regarding the exact payload or credential‑harvesting mechanisms because the site is no longer reachable and no detailed page content has been captured. No TLS fingerprint or certificate data can be evaluated, and the limited number of VirusTotal detections provides only partial insight into the malware families that might have been used.
Defenders should add the domain and its associated IP address to internal blocklists, enforce DNS‑level filtering for the “amlcheckwallet.cc” suffix, and monitor Cloudflare ASN 13335 traffic for any resurgence. Because the domain impersonates the csgo brand, security teams protecting related gaming services should watch for similar brand‑specific lures and consider expanding detection rules to include the “AML Check” title string. Ongoing surveillance of the registrar Dynadot and the observed name servers is recommended to catch future repurposing of the same infrastructure.
威胁响应 Pipeline
公共封禁名单状态
取证情报
VirusTotal 分析
存档证据
证据与外部报告
PD-1769585405-amlcheckwallet. Recipient: abuse@dynadot.com 您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。