bybitrally[.]ru
“Rally Scanner Bybit”
Riepilogo delle prove
bybitrally.ru is currently active and has been classified as a high‑risk brand‑impersonation site targeting users of the cryptocurrency exchange Bybit. The domain was registered on May 7 2026 through the TIMEWEB‑RU registrar and resolves to the IPv4 address 172.86.88.110. Geolocation data places the host in the United States and attributes the infrastructure to FranTech Solutions. The web server runs on Ubuntu with Nginx, is served over a Let's Encrypt certificate (E8), and returns HTTP 200 for the index page whose title reads “Rally Scanner Bybit”. Nameservers are operated by timeweb.ru and timeweb.org.
The site appears on at least one public blocklist and is already blocked by the PhishDestroy service. Reputation services assign low confidence scores: Scamadviser rates the domain 31 / 100, while Gridinsoft scores it 0 / 100. VirusTotal analysis shows a single security vendor flagging the domain out of ninety‑five scanned, indicating limited but present malicious indicators. The page content mimics Bybit branding, likely to harvest credentials or redirect victims to a malicious payload.
Open questions remain regarding the full phishing workflow. No explicit malicious payload, credential‑stealing form, or redirect URL has been captured in the available data, and the specific phishing kit or command‑and‑control infrastructure has not been identified. Continuous monitoring of the IP address and associated subdomains is advisable to detect any escalation in activity.
Defenders should add 172.86.88.110 and the hostname bybitrally.ru to network‑level deny lists, enforce URL filtering for any Bybit‑related traffic, and educate end‑users to verify the official Bybit domain before entering credentials. Incident response teams should capture any attempted connections to this host for forensic analysis and consider sharing observed indicators with community blocklists to improve detection coverage.
Data Coverage
Informazioni sulla sicurezza di rete
Pipeline di risposta alle minacce
Copertura delle blocklist
10 fonti esterne monitorate · snapshot del 11/08/2026
10 fonti esterne monitorate Nessuna corrispondenza
Tecnologie
2 tecnologie identificate con alta affidabilità
Analisi di VirusTotal
Questo sito ti ha influenzato in qualche modo?
Se hai inserito credenziali dell'account, informazioni personali o di pagamento oppure hai scaricato un file da questo dominio, agisci immediatamente. Di seguito sono riportate le risorse per aiutarti a segnalare l'incidente e proteggerti.
Segnalalo alle autorità locali
Seleziona il tuo Paese per ottenere contatti ufficiali del crimine informatico o creare una bozza di reclamo →.
Verifica qualsiasi dominio
Analisi delle minacce utilizzando blocklist archiviate, WHOIS, DNS e prove di scansione pubblica
Scansiona oraSegnala un tentativo di phishing
Segnala i domini sospetti al nostro database delle minacce — proteggi la comunità
SegnalaFeed in tempo reale sulle minacce
Segnalazioni recenti di phishing e modifiche osservate della disponibilità
MonitoraRimani informato, rimani al sicuro
Controlla le minacce in tempo reale oppure contesta questa segnalazione se ritieni che si tratti di un falso positivo