portaltobitcoin[.]run
“Just a moment...”
Registered under PDR Ltd. d/b/a PublicDomainRegistry.com, this domain utilized the IP address 188.114.96.3. It also appeared on multiple blocklists, amplifying its malicious reputation. The domain was recently noted for its suspicious activities and was ultimately taken down due to its fraudulent operations, indicating a pattern of exploitation in the cryptocurrency space.
Currently, the domain status is dead as it has been effectively taken down. PhishDestroy actively reported this domain, contributing to its removal and continues to monitor for any resurgence of similar threats in the future.
Threat Response Pipeline
Public Blocklist Status
Evidence Capture
Domain Intelligence
izabella.ns.cloudflare.com
postmaster@portaltobitcoin.run
contact@portaltobitcoin.run
info@portaltobitcoin.run
webmaster@portaltobitcoin.run
abuse@portaltobitcoin.run
VirusTotal Analysis
Evidence & External Reports
Were You Affected by This Site?
If you have interacted with this domain, entered personal information, or connected a cryptocurrency wallet — take immediate action. Below are resources to help you report the incident and protect yourself.
Report to Your Local Authorities
Select your country to see local cybercrime reporting contacts and complaint templates.
Related Domain Reports
Other Domains on 188.114.96.3
More Domains at PDR Ltd. d/b/a PublicDomainRegistry.com
About This Report: portaltobitcoin.run
This domain security report for portaltobitcoin.run is maintained by PhishDestroy's automated threat intelligence pipeline. Our system continuously monitors this domain across 95 security vendors on VirusTotal, 3 public blocklists, URLScan.io.
The site displays a page titled “Just a moment...”.
portaltobitcoin.run has been flagged by 3 security vendors as of February 27, 2026.
If you believe this listing is inaccurate, you can submit an appeal. For more information about our methodology, visit our FAQ page.
Stay Informed, Stay Safe
Monitor live threats or contest this listing if you believe it's a false positive



URLScan Report