Analysis of prosbybit.com indicates a high-risk phishing domain targeting cryptocurrency users, first registered on April 22, 2026. The domain remains active as of July 28, 2026, and is blocked by PhishDestroy, MetaMask, and SEAL, appearing on three security blocklists. Infrastructure analysis reveals Cloudflare nameservers (mark.ns.cloudflare.com, sandra.ns.cloudflare.com) and resolution to IP 188.114.97.3, a Cloudflare proxy address commonly used to obscure hosting origins. The registrar is NameSilo, LLC, a frequent choice for malicious domains due to privacy and low-cost registration.
VirusTotal scans by 91 vendors show no current detections, though this absence does not confirm legitimacy. No specific phishing kit or brand impersonation details are available from the page title or metadata, but the domain name suggests an attempt to mimic a cryptocurrency exchange or service. The exact content and functionality of the site remain unanalyzed, though the presence on multiple blocklists and the use of Cloudflare for anonymization align with known phishing tactics. Defenders should treat this domain as hostile and prioritize blocking at DNS, proxy, and endpoint levels.
Network monitoring should flag any connections to 188.114.97.3 or resolution attempts for prosbybit.com. If internal logs show user interaction with this domain, initiate credential reset and device isolation procedures. Further analysis of HTTP headers, SSL certificates, or captured page content may reveal additional indicators, but current evidence supports immediate containment.