bybitproe[.]org
Detecção armazenada
Alerta de cloaking
- Tipo de cloaking
status_split- Pontuação de cloaking
- 1/6
Resumo das evidências
Analysis of bybitproe.org shows a newly registered domain created on April 07, 2026 that explicitly targets the Bybit brand. The domain is listed as a fake exchange, indicating it is designed to mislead users into believing it is an official Bybit service. The registration was performed through Dynadot Inc, and the domain is currently active.
Infrastructure analysis reveals that bybitproe.org resolves to the IP address 188.114.97.3, which belongs to Cloudflare, Inc. and is geolocated in Canada. The domain is served by Cloudflare's DNS with the authoritative nameservers andy.ns.cloudflare.com and meera.ns.cloudflare.com. An SSL certificate issued by Google Trust Services under the WE1 label is present, providing encrypted HTTPS connectivity, but HTTP requests return a 403 status code, suggesting intentional access restriction or a defensive measure.
Threat intelligence signals reinforce the malicious profile. The domain appears on one security blocklist and is referenced in an AlienVault OTX pulse, indicating that at least one community source has flagged it. PhishDestroy has also blocked the domain, and Gridinsoft assigns a trust score of 0 out of 100, reflecting extreme suspicion. VirusTotal reports that 5 out of 95 security vendors have flagged the domain as malicious, adding further corroboration from independent scanning engines.
While the available data confirms the domain’s association with a brand impersonation campaign and outlines its technical footprint, the actual web content has not been examined, leaving the precise user‑facing tactics unknown. Defenders should proactively block bybitproe.org and its resolving IP address at network boundaries, update URL filtering and email security policies to include this indicator, and monitor for any related domains that share the same nameservers or registration details. Continuous threat‑intel feeds should be consulted for any new detections linked to the Cloudflare infrastructure used by this actor.
Data Coverage
Pipeline de resposta a ameaças
Cobertura de listas de bloqueio
10 fontes externas monitoradas · instantâneo de 11/08/2026
10 fontes externas monitoradas Sem correspondência
Inteligência de Domínios
Detalhes técnicosDNS, nomes TLS e datas
ICANN OVERSIGHT
Credenciamento e contexto RAA
Credenciamento e contexto RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Análise do VirusTotal
Você foi afetado por este site?
Se você inseriu credenciais de conta, informações pessoais ou de pagamento, ou baixou um arquivo deste domínio, tome medidas imediatas. Abaixo estão os recursos para ajudá-lo a relatar o incidente e se proteger.
Notifique as autoridades locais
Selecione seu país para obter contactos oficiais do cibercrime ou crie um rascunho de reclamação →.
Verificar qualquer domínio
Análise de ameaças usando lista de bloqueio armazenada, WHOIS, DNS e evidências de verificação pública
Digitalize agoraDenunciar phishing
Envie domínios suspeitos para nosso banco de dados de ameaças — proteja a comunidade
DenunciarFeed de ameaças em tempo real
Relatórios recentes de phishing e alterações de disponibilidade observadas
MonitorarMantenha-se informado, mantenha-se seguro
Monitore ameaças em tempo real ou conteste esta listagem caso acredite que se trate de um falso positivo