amlscorecheck[.]net
amlscorecheck.net 网络钓鱼与安全检查
“AMLScoreCheck - Checking cryptocurrency”
amlscorecheck.net — 内容不可用 (HTTP 502). 诈骗类型:Crypto Scam. 证据摘要: VirusTotal 3/93 (Bfore.Ai PreCrime, G-Data, Gridinsoft); 1 external blocklist match (ScamSniffer); PhishDestroy score 65/100.
为保留原始取证记录,下方的 PhishDestroy AI 详细分析仍使用英文。
Analysis of amlscorecheck.net indicates the site was registered on 21 February 2026 and is presently taken offline. The sole page title observed, “AMLScoreCheck – Checking cryptocurrency,” aligns with the classified “Crypto Scam” category. The domain resolves to IP 172.67.168.141, which belongs to Cloudflare, Inc. (ASN 13335) and is geolocated in the United States. TLS is provided by a certificate labeled “WE1,” confirming the presence of encrypted HTTPS service at the time of capture.
Reputation services have flagged the domain on two public blocklists: PhishDestroy and ScamSniffer. VirusTotal scanned the host and recorded 3 positive detections out of 93 scanners, reinforcing the malicious rating. No additional intelligence such as Safe Browsing alerts, Open Threat Exchange mentions, or registrar‑level abuse records were supplied. The limited artifact set prevents a full behavioural profile; the landing page content has not been captured, so the exact user‑interaction flow remains unknown.
However, the combination of recent registration, Cloudflare‑hosted infrastructure, a crypto‑related title, and multiple independent detections qualifies the domain as an elevated‑risk crypto‑focused phishing vector. Defenders should immediately add amlscorecheck.net to URL filtering and DNS block rules, ensure that outbound connections to 172.67.168.141 are denied, and monitor any future attempts to re‑activate the domain. Continuous re‑scanning with VirusTotal and inclusion in threat‑intel feeds are advised to capture any changes to the hosting or payload delivery mechanisms.
威胁响应 Pipeline
公共封禁名单状态
VirusTotal 分析
证据与外部报告
“The PhishDestroy system has identified this domain as a phishing threat, flagged both by our internal parser and reported by users. We also cross-reference with public databases and other antivirus systems.”
您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。