check-amlofficial[.]com
“AML Check”
check-amlofficial.com — 内容不可用. 品牌冒充:Csgo; 诈骗类型:Aml Scam. 证据摘要: VirusTotal 14/95 (ADMINUSLabs, ChainPatrol, alphaMountain.ai, BitDefender, CyRadar); URLQuery 100 det.; CF Radar malicious; PhishDestroy score 100/100. 注册商: PDR.
为保留原始取证记录,下方的 PhishDestroy AI 详细分析仍使用英文。
This domain, check-amlofficial.com, is identified as a phishing site specifically designed to impersonate anti-money laundering (AML) verification portals. The fraudulent page uses the title 'AML Check' to deceive users into submitting sensitive financial credentials, corporate login details, or personal identification information under the pretense of regulatory compliance. Such schemes are commonly employed in business email compromise (BEC) attacks, credential harvesting campaigns, and fraudulent transaction authorization requests targeting financial institutions, compliance officers, and corporate employees. Analysis of the domain infrastructure reveals multiple technical indicators of malicious intent. The domain was registered on March 19, 2025, through PDR Ltd. d/b/a PublicDomainRegistry.com, and currently resolves to the IP address 46.202.158.30, hosted on AS47583 (Hostinger International Limited) in Germany. No SSL certificate is present, increasing the risk of data interception. Security vendors have flagged the domain with a detection ratio of 14/95 on VirusTotal, and it appears on at least one security blocklist. The absence of legitimate encryption, combined with recent registration and confirmed malicious detections, strongly supports the classification of this domain as a high-confidence phishing resource. Users who have visited check-amlofficial.com or entered credentials on the site should take immediate remediation steps. All submitted credentials must be considered compromised and revoked without delay. Affected individuals should reset passwords across all platforms where identical or similar credentials were used, particularly financial and corporate accounts. Enable multi-factor authentication (MFA) on all critical services to mitigate unauthorized access. Monitor financial statements and transaction logs for signs of fraudulent activity, and report any suspicious transactions to relevant financial institutions. Organizations should conduct a review of internal systems for signs of compromise, including unauthorized logins or data exfiltration attempts. If corporate credentials were exposed, initiate an internal security incident response procedure to contain potential lateral movement within the network.
安全信号
网络安全情报
威胁响应 Pipeline
公共封禁名单状态
已保存的截图
域名情报
技术细节DNS、SSL SAN、时间戳
ICANN OVERSIGHT
认证和 RAA 背景
认证和 RAA 背景
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
所用技术 · 1 identified
High-performance HTTP server and reverse proxy, known for stability and low resource usage.
VirusTotal 分析
存档证据
证据与外部报告
您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。