bybitrally[.]ru
“Rally Scanner Bybit”
bybitrally.ru — Não verificado. Representação da marca: Bybit; Tipo de golpe: Brand Impersonation. Resumo das evidências: VirusTotal 4/91 (alphaMountain.ai, CRDF, Gridinsoft, SOCRadar); PhishDestroy score 71/100. Registrador: TIMEWEB-RU.
A análise detalhada do PhishDestroy AI permanece em inglês para preservar o registro forense original.
bybitrally.ru is currently active and has been classified as a high‑risk brand‑impersonation site targeting users of the cryptocurrency exchange Bybit. The domain was registered on May 7 2026 through the TIMEWEB‑RU registrar and resolves to the IPv4 address 172.86.88.110. Geolocation data places the host in the United States and attributes the infrastructure to FranTech Solutions. The web server runs on Ubuntu with Nginx, is served over a Let's Encrypt certificate (E8), and returns HTTP 200 for the index page whose title reads “Rally Scanner Bybit”. Nameservers are operated by timeweb.ru and timeweb.org.
The site appears on at least one public blocklist and is already blocked by the PhishDestroy service. Reputation services assign low confidence scores: Scamadviser rates the domain 31 / 100, while Gridinsoft scores it 0 / 100. VirusTotal analysis shows a single security vendor flagging the domain out of ninety‑five scanned, indicating limited but present malicious indicators. The page content mimics Bybit branding, likely to harvest credentials or redirect victims to a malicious payload.
Open questions remain regarding the full phishing workflow. No explicit malicious payload, credential‑stealing form, or redirect URL has been captured in the available data, and the specific phishing kit or command‑and‑control infrastructure has not been identified. Continuous monitoring of the IP address and associated subdomains is advisable to detect any escalation in activity.
Defenders should add 172.86.88.110 and the hostname bybitrally.ru to network‑level deny lists, enforce URL filtering for any Bybit‑related traffic, and educate end‑users to verify the official Bybit domain before entering credentials. Incident response teams should capture any attempted connections to this host for forensic analysis and consider sharing observed indicators with community blocklists to improve detection coverage.
Inteligência de segurança de rede
Pipeline de resposta a ameaças
Status da lista de bloqueios pública
Tecnologias · 2 identified
Ubuntu is a free and open-source operating system on Linux for the enterprise server, desktop, cloud, and IoT.
www.ubuntu.com 100% de confiançaNginx is a web server that can also be used as a reverse proxy, load balancer, mail proxy and HTTP cache.
nginx.org 100% de confiançaAnálise do VirusTotal
Evidências e relatórios externos
Você foi afetado por este site?
Se você inseriu credenciais de conta, informações pessoais ou de pagamento, ou baixou um arquivo deste domínio, tome medidas imediatas. Abaixo estão os recursos para ajudá-lo a relatar o incidente e se proteger.
Notifique as autoridades locais
Selecione seu país para obter contactos oficiais do cibercrime ou crie um rascunho de reclamação →.
Verificar qualquer domínio
Análise de ameaças usando lista de bloqueio armazenada, WHOIS, DNS e evidências de verificação pública
Digitalize agoraDenunciar phishing
Envie domínios suspeitos para nosso banco de dados de ameaças — proteja a comunidade
DenunciarFeed de ameaças em tempo real
Relatórios recentes de phishing e alterações de disponibilidade observadas
MonitorarMantenha-se informado, mantenha-se seguro
Monitore ameaças em tempo real ou conteste esta listagem caso acredite que se trate de um falso positivo