bitcryptoforestb[.]com
“Vele”
This domain, bitcryptoforestb.com, is flagged as a high-risk crypto-related phishing site based on infrastructure analysis and threat intelligence. Registered on March 25, 2026, through Metaregistrar BV, the domain remains active and resolves to IP address 154.91.82.241. Its nameserver configuration—using a.share-dns.com, a12.share-dns.com, b.share-dns.net, and b12.share-dns.net—aligns with patterns observed in other phishing campaigns, where shared DNS providers are frequently leveraged to obscure ownership and evade takedowns. Analysis indicates the domain has been referenced in at least one threat intelligence pulse, suggesting prior detection by security researchers. While only three of 91 security vendors currently flag the domain, this limited detection rate does not diminish its risk, as phishing domains often evade initial scans before gaining broader attention. The domain’s name, containing 'crypto' and 'forestb,' may imply an attempt to mimic legitimate cryptocurrency platforms, though the exact content and target brand remain unconfirmed due to the absence of page-level analysis. Defenders should treat this domain as actively malicious. Network-level blocking of the IP 154.91.82.241 and its associated nameservers is recommended to disrupt potential phishing operations. Monitoring for connections to this domain or its infrastructure can help identify compromised endpoints. Given the domain’s recent registration and persistent activity, further investigation into its hosting environment and associated campaigns is warranted.
Network Security Intelligence
Threat Response Pipeline
Public Blocklist Status
Stored Capture
Domain Intelligence
Technical detailsDNS, SSL SANs, timestamps
ICANN OVERSIGHT
Accreditation and RAA context
Accreditation and RAA context
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
VirusTotal Analysis
Evidence & External Reports
PD-20260717-F51DFC Recipient: abuse@metaregistrar.com Were You Affected by This Site?
If credentials, payment data, or files were exposed, report the incident immediately. Change affected passwords, revoke active sessions, and scan the device.
Report to Your Local Authorities
Select your country to get official cybercrime contacts, or create a complaint draft →.
Check Any Domain
Threat analysis using stored blocklist, WHOIS, DNS, and public scan evidence
Scan NowReport Phishing
Submit suspicious domains to our threat database — protect the community
ReportLive Threat Feed
Recent phishing reports and observed availability changes
MonitorStay Informed, Stay Safe
Monitor live threats or contest this listing if you believe it's a false positive