usdtamlbot[.]com[.]bybit-invite-copytrading[.]app
“AML Check”
usdtamlbot.com.bybit-invite-copytrading.app — Contenu indisponible (HTTP 502). Usurpation de l'identité de la marque : Csgo; Type d'arnaque : Investment Scam. Résumé des preuves: VirusTotal 8/93 (CRDF, CyRadar, Fortinet, G-Data, Gridinsoft); URLScan malicious verdict; PhishDestroy score 74/100. Bureau d’enregistrement: TLD Registrar Solutions.
L’analyse détaillée de PhishDestroy AI reste en anglais afin de préserver le relevé forensique original.
This report details the technical threat posed by the domain usdtamlbot.com.bybit-invite-copytrading.app. The site presented a page title of "AML Check" and was categorized as an AML Scam, specifically designed to impersonate the csgo brand. The primary threat is that the site likely attempted to deceive users into believing they were performing a legitimate anti-money laundering check, potentially to harvest credentials, financial information, or facilitate unauthorized transactions under the guise of the impersonated brand.
Technical evidence confirms the malicious nature of this domain. VirusTotal analysis recorded 8 out of 95 security vendors detecting the site as malicious. The domain was flagged by CRDF, CyRadar, Fortinet, G-Data, and Gridinsoft, and appeared on 1 blocklist. Its IP address is 82.221.129.24, hosted in Iceland (IS) on AS50613 Advania Island ehf. The domain was registered through TLD Registrar Solutions Ltd and created on 2026-02-21. It utilized an R10 SSL certificate and employed Vue.js with Google Font API technologies. The DOM risk score was assessed at 10, indicating a high level of malicious configuration.
As of the analysis, the domain status is DOWN/OFFLINE. Given the high DOM risk score, the impersonation of a known brand, and the confirmed detections by multiple security vendors, the risk level associated with this domain is assessed as High. The site is no longer accessible, but its history of malicious activity warrants caution.
Processus de réponse aux menaces Pipeline
Statut de la liste de blocage publique
Capture enregistrée
Informations sur les domaines
Détails techniquesDNS, SAN SSL, horodatages
ICANN OVERSIGHT
Registration: bybit-invite-copytrading.app
Contexte de l’accréditation et du RAA
Contexte de l’accréditation et du RAA
Registrar accreditation and DNS abuse obligations
For the registrable domain bybit-invite-copytrading.app behind this subdomain, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Analyse VirusTotal
Données factuelles et rapports externes
Ce site vous a-t-il affecté ?
Si vous avez saisi des informations d'identification de compte, des informations personnelles ou de paiement, ou téléchargé un fichier à partir de ce domaine, agissez immédiatement. Vous trouverez ci-dessous des ressources pour vous aider à signaler l'incident et à vous protéger.
Signalez-le à vos autorités locales
Sélectionnez votre pays pour obtenir contacts officiels en matière de cybercriminalité ou créer un projet de plainte →.
Vérifier n'importe quel domaine
Analyse des menaces à l'aide de listes de blocage stockées, de WHOIS, de DNS et de preuves d'analyse publique
Scanner maintenantSignaler une tentative d'hameçonnage
Signalez les domaines suspects à notre base de données des menaces — protégez la communauté
SignalerFlux d'alertes en temps réel
Rapports de phishing récents et changements de disponibilité observés
SurveillerRestez informés, restez en sécurité
Surveillez les menaces en temps réel ou signalez cette alerte si vous pensez qu'il s'agit d'un faux positif