bituni-web[.]created[.]app
“Join the Crypto Trading Revolution | Register | Bitunix”
The domain bituni-web.created.app is currently classified as a high‑risk generic phishing infrastructure. DNS resolution points exclusively to the IPv4 address 216.150.1.1, and the authoritative name server record returns NS_NOT_FOUND, indicating that conventional nameserver information is absent or concealed. Registration metadata shows the domain was provisioned through the Created App platform, a service often leveraged for rapid deployment of short‑lived web assets. The domain is actively listed on a single security blocklist and is explicitly blocked by the PhishDestroy filtering service, confirming that at least one downstream security product has taken mitigation action.
VirusTotal analysis reveals that one out of ninety‑one submitted security engines raised a detection, suggesting that at least one vendor has identified malicious behavior associated with the host. No additional public threat‑intel feeds such as OTX or Google Safe Browsing have published entries for this host, and no SSL/TLS certificate details, HTTP response codes, or page title information are available from the current dataset. The limited visibility into the web payload means the precise phishing lure and targeted brand remain unknown. However, the combination of a dedicated IP, opaque name server configuration, registration via a bulk‑creation service, and the presence on a commercial blocklist establishes a clear risk profile.
Defenders should continue to block the domain at network perimeters, monitor outbound DNS queries for the 216.150.1.1 address, and add the domain to internal allow‑list exclusions only after thorough verification. Threat‑hunting teams are advised to query endpoint telemetry for any recent connections to the domain or its resolved IP, and to correlate any credential‑theft alerts with this indicator. Ongoing observation is required, as the active status suggests the infrastructure may still be used for credential harvesting or further phishing campaigns.
Threat Response Pipeline
Public Blocklist Status
Stored Capture
Domain Intelligence
Technical detailsDNS, SSL SANs, timestamps
ICANN OVERSIGHT
Registration: created.app
Accreditation and RAA context
Accreditation and RAA context
Registrar accreditation and DNS abuse obligations
For the registrable domain created.app behind this subdomain, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Technologies · 9 identified
Node.js is an open-source, cross-platform, JavaScript runtime environment that executes JavaScript code outside a web browser.
nodejs.org 100% confidenceReact is an open-source JavaScript library for building user interfaces or UI components.
reactjs.org 100% confidenceVercel is a cloud platform for static frontends and serverless functions.
vercel.com 100% confidenceNext.js is a React framework for developing single page Javascript applications.
nextjs.org 100% confidenceLaunchDarkly is a continuous delivery and feature flags as a service platform that integrates into a company's current development cycle.
launchdarkly.com 100% confidenceHTTP Strict Transport Security (HSTS) informs browsers that the site should only be accessed using HTTPS.
www.rfc-editor.org 100% confidenceCloud CDN uses Google's global edge network to serve content closer to users.
cloud.google.com 100% confidenceVirusTotal Analysis
Archived Evidence
Site Performance Analysis
Google PageSpeed Insights — mobile performance audit of bituni-web.created.app · checked Aug 5, 2026
Evidence & External Reports
Were You Affected by This Site?
If credentials, payment data, or files were exposed, report the incident immediately. Change affected passwords, revoke active sessions, and scan the device.
Report to Your Local Authorities
Select your country to get official cybercrime contacts, or create a complaint draft →.
Check Any Domain
Threat analysis using stored blocklist, WHOIS, DNS, and public scan evidence
Scan NowReport Phishing
Submit suspicious domains to our threat database — protect the community
ReportLive Threat Feed
Recent phishing reports and observed availability changes
MonitorStay Informed, Stay Safe
Monitor live threats or contest this listing if you believe it's a false positive