bybit-copy-trade[.]com
“Bybit Copy Trading”
Resumen de las pruebas
On July 24, 2026, the domain bybit-copy-trade.com was identified as a brand‑impersonation site targeting users of the Bybit cryptocurrency exchange. The domain was registered through NiceNIC International Group Co., Limited on 17 July 2025 and resolves to the IPv4 address 146.103.43.235, which is hosted in Germany under autonomous system AS215311 operated by Regxa Company for Information Technology Ltd. No TLS certificate is presented, indicating the site was served over plain HTTP. The sole HTML title returned by the server reads “Bybit Copy Trading”, matching the declared scam type of a crypto‑related fraud. VirusTotal records show that one of ninety‑five scanning engines flagged the domain, and the site is listed on a single external blocklist.
PhishDestroy has also added the domain to its takedown list, and the current status is offline. The observable evidence confirms that the infrastructure was deliberately crafted to suggest an official Bybit copy‑trading service, a common lure for credential harvesting or funds diversion. However, the limited number of detections and the absence of SSL limit the depth of technical attribution; no malware hashes, command‑and‑control endpoints, or additional hosting artifacts have been disclosed. Defenders should immediately block the host IP and the domain at perimeter firewalls and DNS filtering solutions.
Continuous monitoring of the registrar NiceNIC and the associated ASN for new registrations resembling the same naming pattern is advised, as threat actors often reuse the same registration service. Since the site is already offline, incident response teams should still search internal logs for any client connections to the IP address or HTTP requests to the domain to identify potential exposure. Ongoing threat‑intel feeds should be consulted for any resurgence of similar Bybit‑related impersonation campaigns.
Data Coverage
Señales de seguridad
Inteligencia de seguridad de red
Proceso de respuesta ante amenazas Pipeline
Cobertura de listas de bloqueo
10 fuentes externas supervisadas · instantánea del 13/08/2026
10 fuentes externas supervisadas Sin coincidencias
Evidencia del resultado almacenada
Resultado y atribución del retiro
- Resultado
held- Disponibilidad
unreachable- Causa
registrar_client_hold- Actor
- NICENIC INTERNATIONAL GROUP CO., LIMITED
- Mecanismo
client_hold- Confianza
- 95%
- Primera observación
- Última observación
Indisponibilidad estimada
Tiempo hasta la indisponibilidad: 0 hSHA-256 de la evidencia 95fc273170bc
Cronología de detección
-
Cloudflare Radar
Análisis de Cloudflare Radar almacenado · Abrir análisis
-
Disponibilidad
Primer valor almacenado: DNS inactivo
f93a11f87e4d -
Disponibilidad
DNS inactivo → Desconocido
07fecc839d15 -
Disponibilidad
Desconocido → Retenido
c0a5b15ff4aa -
Disponibilidad
Retenido → Inactivo
fa84b4a1f67f -
Disponibilidad
Inactivo → DNS inactivo
3f586be91040 -
Disponibilidad
DNS inactivo → Desconocido
c3e4ac25b4e2 -
Disponibilidad
Desconocido → Retenido
8a7cebd7a5e3 -
Disponibilidad
Retenido → Desconocido
5bbf4bed9ecd -
Disponibilidad
Desconocido → DNS inactivo
6dfe9145995c
Mostrar todo (16)
-
Disponibilidad
DNS inactivo → Retenido
2b9b67c78b81 -
Disponibilidad
Retenido → DNS inactivo
641ed81dc4d5 -
Disponibilidad
DNS inactivo → Desconocido
7bff7f82baae -
Disponibilidad
Desconocido → Retenido
be31a7951654 -
Disponibilidad
Retenido → Desconocido
e508a0dd6e80 -
Disponibilidad
Desconocido → DNS inactivo
d0b7046e8c2f -
Disponibilidad
DNS inactivo → Retenido
2dd7f31bf7d7 -
Disponibilidad
Retenido → DNS inactivo
ca9ed662b468 -
Disponibilidad
DNS inactivo → Desconocido
fed594883962 -
Disponibilidad
Desconocido → Retenido
7c1f29855332 -
Disponibilidad
Retenido → DNS inactivo
92f667ff6e00 -
Disponibilidad
DNS inactivo → Desconocido
62c63d288670 -
Disponibilidad
Desconocido → Retenido
2084b01a586f -
Disponibilidad
Retenido → DNS inactivo
9eda8dc3b7e8 -
Disponibilidad
DNS inactivo → Desconocido
645e2b82e869 -
Disponibilidad
Desconocido → Retenido
95fc273170bc
Reportes de la comunidad
Reportado por 1 miembro de la comunidad; visto por primera vez el 22/07/2025
- Reportes almacenados
- 1
- URL únicas reportadas
- 1
Captura guardada
Inteligencia de dominios
Detalles técnicosDNS, nombres TLS y marcas de tiempo
ICANN OVERSIGHT
Acreditación y contexto RAA
Acreditación y contexto RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Inteligencia forense
Análisis de VirusTotal
Dominios similares
112 dominios similares almacenados
Mostrar todo (88)
Se muestran 100 de 112
¿Te ha afectado esta página web?
Si ingresó credenciales de cuenta, información personal o de pago, o descargó un archivo de este dominio, tome medidas inmediatas. A continuación encontrará recursos que le ayudarán a informar el incidente y protegerse.
Informa a las autoridades locales
Seleccione su país para obtener contactos oficiales de cibercrimen o crear un borrador de queja →.
Comprobar cualquier dominio
Análisis de amenazas utilizando listas de bloqueo almacenadas, WHOIS, DNS y evidencia de escaneo público
Escanear ahoraDenunciar un intento de phishing
Envía los dominios sospechosos a nuestra base de datos de amenazas: protege a la comunidad
DenunciarFlujo de amenazas en tiempo real
Informes de phishing recientes y cambios de disponibilidad observados
MonitorizarMantente informado, mantente a salvo
Supervisa las amenazas en tiempo real o impugna esta entrada si crees que se trata de un falso positivo.