MALICIOUS — HIGH
app[.]bitlay[.]pro
The domain app.bitlay.pro was a phishing site engaged in brand impersonation targeting users of the cryptocurrency platform 'across'.
- VirusTotal
- 2/93
- Blocklists
- No stored match
- Disponibilidade
- Conteúdo indisponível · HTTP 502
Do not enter credentials, seed phrases, payment details, or personal information on this domain.
Jump to section
app.bitlay.pro — Conteúdo indisponível (HTTP 502). Representação da marca: Across; Tipo de golpe: Crypto Scam. Resumo das evidências: VirusTotal 2/93 (Fortinet, Gridinsoft); PhishDestroy score 56/100.
A análise detalhada do PhishDestroy AI permanece em inglês para preservar o registro forense original.
Evidence Analysis
The domain app.bitlay.pro was a phishing site engaged in brand impersonation targeting users of the cryptocurrency platform 'across'. It posed as a legitimate cryptocurrency trading and investment service to deceive victims into disclosing sensitive information or transferring funds. No drainer kit was identified, but the site operated as a cryptocurrency scam. As of the latest verification, app.bitlay.pro has been taken offline.
Technical indicators confirm the malicious nature of app.bitlay.pro. The domain was flagged by 2 of 95 security vendors on VirusTotal, including Fortinet and Gridinsoft, and appeared on 1 security blocklist (PhishDestroy). It was created on February 21, 2026, and resolved to the IP address 66.29.148.6, hosted by Namecheap, Inc. in the US (AS22612). The SSL certificate was issued by R11, and the observed page title was 'Cryptocurrency trading and invest platform'. Google Safe Browsing did not flag the domain at the time of analysis.
Victims of app.bitlay.pro should take immediate action to secure their assets and accounts. If cryptocurrency transactions were attempted, revoke any token approvals and transfer remaining funds to a new wallet. For credential or login phishing, change passwords on all affected accounts, enable two-factor authentication, and monitor for unauthorized activity. Report the incident to the impersonated brand 'across' and submit the domain to platforms like PhishTank or Google Safe Browsing for further blocking.
Cobertura dos dados12 recorded checks
Pipeline de resposta a ameaças
Status da lista de bloqueios pública
Análise do VirusTotal
Evidências e relatórios externosIndependent lookups and source reports
Victim safety and official reportingImmediate actions and verified reporting channels
Se você inseriu credenciais de conta, informações pessoais ou de pagamento, ou baixou um arquivo deste domínio, tome medidas imediatas. Abaixo estão os recursos para ajudá-lo a relatar o incidente e se proteger.
Notifique as autoridades locais
Selecione seu país para obter contactos oficiais do cibercrime ou crie um rascunho de reclamação →.