MALICIOUS — CRITICAL
bybitwebio.my — Brand Impersonation Report
bybitwebio[.]
The domain bybitwebio.my was first registered on August 01, 2025 through Dynadot LLC and is currently listed as offline.
- VirusTotal
- 12/91
- Blocklists
- No stored match
- Verfügbarkeit
- Letzter bekanntermaßen aktiv · HTTP 200
Do not enter credentials, seed phrases, payment details, or personal information on this domain.
Jump to section
bybitwebio.my — Letzter bekanntermaßen aktiv (HTTP 200). Markenidentität: Bybit; Betrugstyp: Crypto Scam. Zusammenfassung der Beweislage: VirusTotal 12/91 (alphaMountain.ai, BitDefender, Chong Lua Dao, CRDF, CyRadar); PhishDestroy score 96/100. Registrar: Dynadot.
Die ausführliche Analyse von PhishDestroy AI bleibt auf Englisch, damit der ursprüngliche forensische Bericht unverändert bleibt.
Evidence Analysis
The domain bybitwebio.my was first registered on August 01, 2025 through Dynadot LLC and is currently listed as offline. DNS resolution points to the IPv4 address 206.119.171.228, which resides in Japan and is announced by AS133199 belonging to SonderCloud Limited. The authoritative nameservers are ns1.dyna-ns.net and ns2.dyna-ns.net. No SSL/TLS certificate is presented for the host, indicating that HTTPS connections are not supported.
The only visible credential is the page title "Bybit Digital Trading Platform," which aligns with the declared brand target of Bybit and the classified scam type of a crypto scam. The site has been blocked by the PhishDestroy blocklist and appears on one additional security blocklist. VirusTotal analysis records that seven out of ninety‑five scanning engines flagged the domain as malicious, reinforcing the suspicion of abuse. Risk assessment rates the threat as elevated.
While the domain is presently offline, the underlying IP address and hosting infrastructure remain active and could be reused for future campaigns. Defenders should therefore add both the domain and the associated IP (206.119.171.228) to deny‑list configurations, monitor DNS queries for the listed nameservers, and incorporate the observed detection pattern into threat‑intel feeds. Continuous re‑scanning of the IP and any newly resolved subdomains is recommended to capture potential re‑deployment of the impersonation infrastructure.
Stored source results
Recorded verdicts and infrastructure observations for this domain.
Datenabdeckung14 recorded checks
Sicherheitssignale
Pipeline zur Reaktion auf Sicherheitsbedrohungen
Status der öffentlichen Sperrliste
Forensische Erkenntnisse
VirusTotal-Analyse
Archivierte Beweise
Analyse der Website-Konfiguration
Nachweise und externe BerichteIndependent lookups and source reports
Victim safety and official reportingImmediate actions and verified reporting channels
Wenn Sie Kontoanmeldeinformationen, persönliche oder Zahlungsinformationen eingegeben oder eine Datei von dieser Domain heruntergeladen haben, ergreifen Sie sofort Maßnahmen. Nachfolgend finden Sie Ressourcen, die Ihnen helfen, den Vorfall zu melden und sich zu schützen.
Melden Sie sich bei Ihren örtlichen Behörden
Wählen Sie Ihr Land aus, um Offizielle Kontakte im Bereich Cyberkriminalität oder einen Beschwerdeentwurf erstellen → zu erhalten.