⚠️
تم الإبلاغ عن هذا النطاق باعتباره ضارًّا
Detected by 7 security vendors. Exercise extreme caution — do not enter personal information or connect wallets. إنشاء خطاب شكوى رسمي مدعوم بالذكاء الاصطناعي لتقديمه إلى سلطات مكافحة الجرائم الإلكترونية.
dbybits.com favicon

dbybits[.]com

تقرير أمن النطاقات ومعلومات التهديدات

“Подключение кошелька Bybit к DApp - App (Web3)”

7/91 VT Active threat Jul 19, 2025 Unavailable since Feb 15, 2026 Bybit Crypto Scam 1 Report Sent US US + more
10 درجة المخاطر
ملخص التقرير المترجم

dbybits.com: ‏7/91 اكتشافات في VirusTotal. راجع DNS وSSL والمسجّل وقوائم الحظر وأدلة التهديد.

يبقى تحليل PhishDestroy AI المفصل أدناه باللغة الإنجليزية للحفاظ على السجل الجنائي الرقمي الأصلي.

PhishDestroy AI
HIGH
Ref
B90925BC
Score
10/100
Engine
PD-4 Turbo
This domain dBybits[.]com is actively hosting a brand-impersonation site that claims to connect a Bybit wallet to a DApp, as indicated by the page title “Подключение кошелька Bybit к DApp - App (Web3)”. The site is registered through Amazon Registrar, Inc. on 25 January 2025 and resolves to the IP 157.185.160.145, which belongs to AS54994 Meteverse Limited in the United States. The HTTPS certificate is issued by Amazon (RSA 2048 M04), and the server stack includes Nginx, OpenResty, React, and Amazon Web Services, with sign-in integrations for Google and Apple. Advertising components from Twitter Ads and MGID are also detected. Six of ninety‑five VirusTotal scanners have flagged the domain, and it appears on at least one external security blocklist as well as being blocked by PhishDestroy. Reputation services assign a Gridinsoft score of 10/100 and a Scamadviser score of 10/100, reinforcing the malicious assessment. The site returns an HTTP 301 redirect, suggesting an attempt to funnel traffic to another location, but the final landing page has not been captured in this report. Defenders should block DNS resolution for dbybits[.]com, monitor outbound connections to its IP address, and enforce email filtering rules that detect references to Bybit wallet connections. Incident response teams should treat any credential or private-key submissions to this domain as compromised and advise affected users to rotate credentials and revoke any associated keys. Continuous monitoring of the associated IP range and the hosting provider may reveal further related infrastructure.
VirusTotal
VirusTotal
7 det.
URLScan
URLScan
Gridinsoft
0/100
ScamAdviser
Scamadviser
11/100
العمر
1.5 yr
Observed status
Active threat 301
PhishDestroy
قائمة الإتلاف
Listed
Reports Sent
1
نطاق تغطية البيانات VirusTotal 7 / 91 URLQuery no detections OTX no pulses رادار CF clean URLScan report ready حجب عناوين DNS none SSL no cert WHOIS 18 mo old Screenshot لم يتم تسجيله سلسلة إعادة التوجيه not probed Gridinsoft 0/100 Scamadviser 11/100
مؤشرات الأمان
SA Scamadviser Warnings 11/100
The website's owner is hiding his identity on WHOIS using a paid service This website does not have many visitors We detected cryptocurrency services which can be high risk Possible high risk financial services detected This website has only been registered recently. It appears that this website trades NFTs Pulsedive reports elevated risk with this website.
According to the SSL check the certificate is valid DNSFilter considers this website safe

مسار الاستجابة للتهديدات Pipeline

Discovery
Checks
Reports
Availability
13/14
الاكتشاف والاستيعاب الاستباقي
تم استيعاب التهديد
1/1 ✓
تم استيعاب التهديد
dbybits.com تم اكتشافها وإدراجها في قائمة الانتظار لإجراء تحليل شامل
Jul 19, 2025
Threat Intelligence Checks
URLScan.io Snapshot · Cloudflare Radar · Web Archive · VirusTotal · Google Safe Browsing · Brand Impersonation · Forensic Evidence Collected · Technical Analysis Recorded · VT Detection +1 · VT Detection -2
10/10 ✓
URLScan.io Snapshot
Submitted to urlscan.io — screenshot, DOM & HTTP transactions captured
Mar 06, 2026
رادار Cloudflare
Scanned via رادار Cloudflare — DNS, certificates & network data
Web Archive
Preserved in آلة الزمن — historical evidence archived
VirusTotal
7 / 91 vendors flagged on VirusTotal
Jul 28, 2026
Google Safe Browsing
Mar 02, 2026
Brand Impersonation
Impersonation of Bybit
Forensic Evidence Collected
Stored evidence from URLScan.io, stored screenshot
Mar 06, 2026
Technical Analysis Recorded
The report contains stored technology or forensic-analysis results
Aug 01, 2026
VT Detection +1
+1 new detection (6 → 7): ADMINUSLabs, SOCRadar
Mar 10, 2026
VT Detection -2
2 detections removed (6 → 4)
Mar 02, 2026
Notification Records
تم إرسال تقارير عن حالات الإساءة
1/1 ✓
تم إرسال تقارير عن حالات الإساءة
تم إرسال تقرير عن حالة إساءة معاملة إلى أمين السجل Amazon Registrar, Inc., hosting provider
Jul 19, 2025
النشر والتوافر
DestroyList Published · Monitoring Continues
1/2
تم نشر قائمة «DestroyList»
Jul 19, 2025
Monitoring Continues
The domain remains reachable or access-restricted; future checks may update this observation

حالة قوائم الحظر العامة

جمع الأدلة

Live Snapshot
2025-07-19 05:24 UTC
Malicious · 7/91 engines
Forensic screenshot of dbybits.com showing the phishing page layout
IP: 157.185.160.145
Amazon Registrar, Inc.
553d old
Page Title
Подключение кошелька Bybit к DApp - App (Web3)
Impersonates
Bybit Google Mantle Metamask Uniswap
TLS Certificate
Valid · Issued by Amazon / Amazon RSA 2048 M04 · valid for 217 days

معلومات النطاق

Domaindbybits.com
Registrar Amazon US(US)
IP Address 157.185.160.145 US
GeoUS Ashburn, US
NetworkASAS54994 · AS54994 Meteverse Limited.
Registrationتم إنشاؤه Jan 25, 2025 Expires Aug 18, 2025
حالة HTTP301 Moved Permanently
Elapsed Since First Report 239 days
What we count Raw elapsed time since the first stored abuse report. It is not a registrar response-time measurement. Latest observed status: Active threat.
What each report contains Stored outgoing report records may reference evidence available at the time, such as vendor verdicts, registration data, hosting details, classifications, or screenshots. This page does not infer the exact payload delivered, receipt, acknowledgement, or action by a recipient.
التفاصيل الفنيةDNS، أسماء المجال البديلة (SAN) في بروتوكول SSL، الطوابع الزمنية
تاريخ أول اكتشافJul 19, 2025
Nameservers1
TLS Fingerprintcedab966114e9702e2e184e846c0d6a5544ac6b7…
TLS SAN Domainsc-by-bit.comcbybit.comcbybitapp.comd-by-bit.comebybit.netfbybit.comhbybit.netjbybit.comlovebybit.com
إشراف ICANN · تم تحصيل الرسوم

حصلت ICANN على أموالها. أما المساءلة فلم تصل.

بالنسبة إلى نطاق gTLD هذا، يعمل المسجّل المذكور أعلاه بموجب عقد مع ICANN. وتحصّل ICANN رسوماً سنوية ومتغيرة ورسومًا قائمة على المعاملات مرتبطة بعمليات التسجيل والتجديد والنقل.

الاعتماد: جرت الاستفادة منه مالياً. المساءلة: يُرجى التحقق مرة أخرى لاحقاً.

ثم يبدأ السحر: تكتب ICANN البند RAA §3.18، ويتولى المسجّل التحقيق في إساءة الاستخدام داخل قاعدة عملائه، ويقدّم الضحايا الأدلة مجاناً، بينما تنتظر كل طبقة أن يتحرك طرف آخر. إذا كان ذلك يجعل الضحايا يشعرون بمزيد من الأمان، فممتاز—لقد أدّت الفاتورة مهمتها.

ملاحظة ساخرة عن المساءلة لا يُرسل أي شيء تلقائياً.
عناصر الحملة المرتبطة · 8 sharing fingerprint
Other tracked phishing domains sharing this site’s infrastructure fingerprint: Amazon Registrar, Inc. Bybit — suggests a coordinated kit / operator cluster.
kbybit.com
Alive 14 VT
learn.jbybit.com
Cloaked — alive 6 VT
www.hbybit.net
Cloaked — alive 9 VT
learn.kbybit.com
Cloaked — alive 16 VT
learn.cbybitapp.com
Cloaked — alive 17 VT
learn.hbybit.net
Alive 11 VT
learn.c-by-bit.com
Cloaked — alive 15 VT
learn.bitewater.net
Cloaked — alive 14 VT
Explore the Domain Hub Filter hub by this fingerprint
التقنيات · 17 identified
Google Sign-in
A
Apple Sign-in
Nginx
Web servers Reverse proxies

High-performance HTTP server and reverse proxy, known for stability and low resource usage.

React
JavaScript frameworks

JavaScript library for building user interfaces with component-based architecture.

OpenResty
Web servers

Web platform based on Nginx with LuaJIT for scalable web apps.

Amazon Web Services
PaaS IaaS

Cloud computing platform offering compute, storage, and networking services.

Twitter Ads

Conversion and audience tracking pixel for paid campaigns on X (Twitter) — signals that the site runs paid X ads.

business.x.com
MGID
Linkedin Insight Tag

Conversion-tracking pixel by LinkedIn — B2B ad audience measurement.

Linkedin Ads
HSTS
Security

HTTP Strict Transport Security — forces browsers to use HTTPS connections only.

Google Tag Manager
Tag managers

Tag management system for deploying marketing and analytics tags.

tagmanager.google.com
Google Analytics
Analytics

Web analytics service tracking website traffic and user behavior.

marketingplatform.google.com
Facebook Pixel

Conversion-tracking pixel by Meta — logs page views and custom events to Facebook/Instagram ad accounts.

www.facebook.com
DigiCert
Akamai
HTTP/3
Miscellaneous

Third major version of HTTP protocol, built on QUIC for faster, more reliable connections.

Detected via رادار Cloudflare · Wappalyzer engine
الإبلاغ عن هذا النطاق أرسل الأدلة وساعد في حماية الآخرين

تحليل VirusTotal

7 / 91 security vendors flagged this domain
View on VT
ADMINUSLabs
alphaMountain.ai
CyRadar
Forcepoint ThreatSeeker
Fortinet
Gridinsoft
Webroot

الأدلة المؤرشفة

Wayback Machine Snapshot
A historical snapshot is available for evidence review
View Archive
تحليل أداء الموقع

Google PageSpeed Insights — mobile performance audit of dbybits.com · checked Mar 2, 2026

28
Poor
Performance
FCP
4.53s
First Contentful Paint
LCP
12.96s
Largest Contentful Paint
CLS
0.092
Cumulative Layout Shift
TBT
1847ms
Total Blocking Time
SI
9.03s
Speed Index
Powered by Google PageSpeed Insights · Mobile strategy · Scores: 90-100 Good 50-89 Needs Work 0-49 Poor

الأدلة والتقارير الخارجية

نظام أسماء النطاقات (DNS) والشبكات
تحسين محركات البحث (SEO) والنطاقات

هل تأثرت بهذا الموقع؟

أنت لست وحدك، ولا يوجد ما يدعو للخجل. المحتالون هم مجرمون ماهرون يستغلون ثقة الناس. ويُعد الإبلاغ عن تجربتك أقوى سلاح لمكافحة الاحتيال — فإبلاغك هذا يمكن أن يمنع وقوع ضحايا جدد ويساعد سلطات إنفاذ القانون على اتخاذ الإجراءات اللازمة. الصمت هو أكبر ميزة للمحتال. حطّمه.

إذا كنت قد تفاعلت مع هذا النطاق، أو أدخلت معلومات شخصية، أو قمت بربط محفظة عملة مشفرة — فاتخذ إجراءات فورية. فيما يلي بعض الموارد التي تساعدك على الإبلاغ عن الحادث وحماية نفسك.

احذروا من المحتالين الذين يزعمون أنهم يساعدون في استرداد الأموال! بعد تعرضك لعملية احتيال، قد يتصل بك المجرمون مرة أخرى متظاهرين بأنهم «وكلاء استرداد» أو محامون أو محققون، ويزعمون أنهم قادرون على استرداد أموالك المفقودة — مقابل رسوم. هذه عملية احتيال ثانية. لن تطلب أي خدمة شرعية دفع مبلغ مقدمًا لاسترداد العملات المشفرة المسروقة. تعرف على المزيد حول الاحتيال في مجال التعافي →

أبلغ السلطات المحلية

اختر بلدك للحصول على جهات الاتصال الرسمية المعنية بجرائم الإنترنت, or إنشاء شكوى مدعومة بالذكاء الاصطناعي →

اختر بلدك...
أكثر من 180 دولة
Zero-PII — بياناتك لا تغادر المتصفح أبدًا الذكاء الاصطناعي يكتب بلغتك

تقارير النطاقات ذات الصلة

ledgerlive.su
ledgerlive.su
3 detections · Unavailable · Similar title
instagramhelp.whf.bz
instagramhelp.whf.bz
21 detections
app.meopex.com
app.meopex.com
12 detections
gooddogshop.click
gooddogshop.click
22 detections
go.puotox.com
go.puotox.com
12 detections
defilllama.com
defilllama.com
15 حالة اكتشاف
defilllama.at
defilllama.at
5 detections

Other Domains on 157.185.160.145 6 phishing domains

This IP hosts multiple phishing domains — infrastructure shared across campaigns

learn.cbybitapp.com favicon learn.cbybitapp.com 17/95 learn.kbybit.com favicon learn.kbybit.com 16/95 learn.c-by-bit.com favicon learn.c-by-bit.com 15/95 learn.bitetea.com favicon learn.bitetea.com 14/95 learn.bitetea.net favicon learn.bitetea.net 14/95 learn.bitewater.net favicon learn.bitewater.net 14/95

More Domains at Amazon تم الإبلاغ عن 6 مشاركات

oucnyi.kim favicon oucnyi.kim 15/95 app.library.mmb-legacy-dev.magiclabs-aurora.io favicon app.library.mmb-legacy-dev.magiclabs-aurora.io 4/95 ibt.dhlevripremium.com favicon ibt.dhlevripremium.com 13/95 www.unidkjuy.com favicon www.unidkjuy.com 7/95 www.hotsdrama.com favicon www.hotsdrama.com 3/95 ruteforing.speed.bioignites.org favicon ruteforing.speed.bioignites.org 24/95

Other Bybit Impersonation Domains

These domains also target Bybit users. View all Bybit threats →

audit-defi.com audit-defi.com 23 bybit.com.online-dex.sbs bybit.com.online-dex.sbs 22 bybit-auditor.one bybit-auditor.one 21 sdd.baby sdd.baby 21 bybit-auditor.app bybit-auditor.app 20 bybitenur.com bybitenur.com 20 bym9n.mobi bym9n.mobi 20 trust-bybit.click trust-bybit.click 20

About This Report: dbybits.com

This report presents the latest stored evidence available to PhishDestroy. Source timestamps are shown where available; availability and vendor verdicts can change after collection.

The site displays a page titled “Подключение кошелька Bybit к DApp - App (Web3)”, which may be designed to impersonate Bybit.

dbybits.com has been flagged by 7 security vendors as of August 1, 2026.

إذا كنت تعتقد أن هذه القائمة غير دقيقة، فيمكنك تقديم استئناف. لمزيد من المعلومات حول منهجيتنا، يرجى زيارة موقعنا صفحة الأسئلة الشائعة.

تحقق من أي نطاق

Threat analysis using stored blocklist, WHOIS, DNS, and public scan evidence

امسح الآن

الإبلاغ عن محاولة تصيد احتيالي

أرسل النطاقات المشبوهة إلى قاعدة بيانات التهديدات الخاصة بنا — ساهم في حماية المجتمع

Report

تحديثات فورية حول التهديدات

Recent phishing reports and observed availability changes

Monitor

ابقَ على اطلاع، وابقَ آمنًا

راقب التهديدات في الوقت الفعلي أو اعترض على هذا الإدراج إذا كنت تعتقد أنه إنذار كاذب

تحديثات فورية حول التهديدات الاعتراض على هذا الإعلان

توصيات ونصائح للضحايا

يُقدَّر أن $51 billion تدفقت إلى محافظ عملات مشفرة غير مشروعة في عام 2024 (source). إذا كنت قد تفاعلت مع dbybits.com — تصرف الآن.

ما الذي يجب أن أفعله على الفور؟
Urgent
  • إلغاء الموافقات على الرموز — use revoke.cash لإلغاء الصلاحيات الممنوحة للعقود الذكية الضارة
  • تحويل الأموال المتبقية إلى محفظة جديدة تمامًا. المحفظة التي تعرضت للاختراق لم تعد آمنة
  • تغيير جميع كلمات المرور — البريد الإلكتروني، وحسابات «إكستشينج»، وأي شيء يستخدم نفس كلمة المرور
  • تمكين المصادقة الثنائية (2FA) باستخدام تطبيق المصادقة (وليس الرسائل النصية القصيرة). تعطيل الاستعادة عبر الرسائل النصية القصيرة
  • بطاقات التجميد إذا قمت بإدخال بياناتك المصرفية على موقع التصيد الاحتيالي
ما هي المعلومات التي يجب أن أجمعها لإعداد تقريري؟
إرشادات مكتب التحقيقات الفيدرالي (FBI)

وفقًا لـ FBI، وأهم التفاصيل هي بيانات المعاملات:

  • عناوين العملات المشفرة — محفظة المحتال (على سبيل المثال، 0x5856...35985)
  • المبلغ ونوع العملة المشفرة — المبلغ الدقيق (على سبيل المثال، 1.02345 ETH، 0.5 BTC، 500 USDT)
  • معرّف المعاملة (هاش) — المعرّف الفريد لمعاملة البلوكشين
  • التواريخ والأوقات الدقيقة — لكل معاملة ولأول اتصال مع المحتال
  • Screenshots — مواقع الويب الاحتيالية، ورسائل الدردشة، ورسائل البريد الإلكتروني، ومعاملات المحافظ الرقمية، ووسائل التواصل الاجتماعي
  • جميع عناوين URL والنطاقات التي يستخدمها المحتال (بما في ذلك dbybits.com)
  • Communications — رسائل البريد الإلكتروني، والرسائل النصية، وأرقام الهواتف، وأسماء المستخدمين التي استخدمها المحتال

حتى لو لم تكن جميع التفاصيل متوفرة — تقديم بلاغ على أي حال. فحتى المعلومات الجزئية تساعد في التحقيقات.

إلى أين يجب أن أبلغ عن عملية الاحتيال؟
  • مركز IC3 التابع لمكتب التحقيقات الفيدرالي (FBI) — مركز شكاوى الجرائم الإلكترونية (الإبلاغ على المستوى الفيدرالي في الولايات المتحدة)
  • Europol — الإبلاغ عن الجرائم الإلكترونية في أوروبا (الاتحاد الأوروبي)
  • Chainabuse — الإبلاغ عن المحافظ المشبوهة عبر البورصات والمنصات المختلفة
  • منصة تداول العملات المشفرة الخاصة بك — اتصل بدعم العملاء في Coinbase/Binance/Kraken لتجميد عنوان المحتال
  • الشرطة المحلية — يُنشئ سجلاً رسمياً، حتى لو لم يتمكن من اتخاذ إجراء فوري

استعاد مكتب التحقيقات الفيدرالي (FBI) أكثر من مليار دولار في قضايا الاحتيال المتعلقة بالعملات المشفرة في عام 2024، وذلك بفضل البلاغات التي قدمتها الضحايا. تقريرك مهم.

كيف تعمل عمليات الاحتيال في مجال العملات المشفرة عادةً؟
  • المواقع الإلكترونية المزيفة — نسخ مطابقة تمامًا للمواقع الأصلية، مع تغيير طفيف في عناوين النطاقات
  • الموافقات الخبيثة — مطالبات «connect wallet» التي تمنح المهاجمين صلاحية إنفاق غير محدودة للرموز الرقمية
  • pig butchering — بناء الثقة على مدى أسابيع عبر Telegram/واتساب/تطبيقات المواعدة، ثم سرقة الأموال
  • عمليات الاحتيال المتعلقة باسترداد الأموال — تعرض الضحايا مرة أخرى للاستهداف من قِبل «وكلاء استرداد» مزيفين يطالبون بدفع رسوم مقدماً. دائمًا ما تكون عملية احتيال
  • الإعلانات المزيفة وعمليات التوزيع المجاني — إعلانات جوجل ووسائل التواصل الاجتماعي وعروض «الرموز المجانية» التي تؤدي إلى استنزاف رصيد المحفظة
  • عمليات الاحتيال التي تعتمد على الذكاء الاصطناعي — تقنية «ديب فايك»، والتصيد الاحتيالي الآلي، والمواقع التي يُنشئها الذكاء الاصطناعي، مما يجعل الكشف عن عمليات الاحتيال أكثر صعوبة
كيف يمكنني حماية نفسي في المستقبل؟
  • استخدم محفظة مادية (ليدجر، تريزور). لا تقم أبدًا بتخزين مبالغ كبيرة في محافظ المتصفح
  • إضافة المواقع الرسمية إلى قائمة المفضلة — لا تنقر أبدًا على الروابط الواردة في رسائل البريد الإلكتروني أو الرسائل المباشرة أو الإعلانات
  • اقرأ كل موافقة — التحقق من الأذونات قبل التوقيع. رفض الموافقات غير المحدودة
  • التحقق من النطاقات — التحقق من PhishDestroy قبل التفاعل. تحقق من HTTPS، والتهجئة، وعمر النطاق
  • "أمر جيد لدرجة يصعب تصديقها" = عملية احتيال — عوائد مضمونة، وتأييد المشاهير، ومواعيد نهائية ملحة
ما مدى خطورة مشكلة عمليات الاحتيال في مجال العملات المشفرة؟
  • $51 billion تدفقت إلى محافظ عملات مشفرة غير مشروعة في عام 2024 — CoinLedger
  • pig butchering ارتفعت الخسائر بنسبة 40% مقارنة بالفترة نفسها من العام الماضي، وأصبحت الآن أسرع أنواع الاحتيال نموًّا
  • لا يبلغ عن الحادث سوى حوالي 5٪ من الضحايا — تقريرك يساعد في تفكيك الشبكات الإجرامية
  • استرد مكتب التحقيقات الفيدرالي (FBI) أكثر من مليار دولار في عام 2024 بفضل بلاغات الضحايا — FBI.gov

المصادر: FBI · CoinLedger · WorldMetrics

رسالة شكر صادقة جداً

منشئ مسودة ساخرة

المستلم
سياق الرسوم

مسودة ساخرة. أرقام الرسوم تقديرية، ولا ندّعي نسبتها بدقة إلى هذا النطاق.

تضمين هذا التقرير

شارك هذه المعلومات الاستخباراتية المتعلقة بالتهديدات على موقعك الإلكتروني أو مدونتك