Analysis of the domain bank-bit.com indicates an active banking‑phishing infrastructure. The domain was registered on October 13, 2024 through NICENIC INTERNATIONAL GROUP CO., LIMITED and currently resolves to the IPv4 address 91.92.241.159. Authoritative DNS is provided by ns1.metaquotes.business and ns2.metaquotes.business, both of which are typical of low‑cost hosting services and do not reveal a corporate affiliation. The site has been blocked by the PhishDestroy sinkhole and appears on one external security blocklist, confirming that at least one defensive community has observed malicious activity linked to this host.
VirusTotal records show that the domain was submitted to 91 scanning engines; none of the engines raised a detection at the time of analysis, though the absence of a detection does not equate to safety. No additional public intelligence such as page titles, SSL certificate details, or brand‑specific cues have been disclosed, leaving the exact phishing landing page content uncertain. Despite limited surface‑level evidence, the combination of recent registration, dedicated nameservers, a single‑purpose IP address, and inclusion on a phishing blocklist strongly suggests that the domain is being used to harvest banking credentials.
Defenders should proactively block bank-bit.com and its resolving IP address at perimeter firewalls, DNS resolvers, and endpoint protection solutions. Continuous monitoring of the associated IP and the hosting provider for new domains is recommended, as threat actors frequently reuse infrastructure. Inclusion of the domain in local blocklists and threat‑intel feeds will reduce exposure while further investigative work, such as sandboxed URL retrieval, can confirm the payload and victim‑targeting specifics.