bitreem[.]com
“Secure Global Crypto Exchange | Bitreem.com”
PhishDestroy identifies bitreem.com as an ACTIVE phishing domain currently under investigation for impersonating cryptocurrency investment platforms and phishing for Bitcoin wallet credentials. The domain poses a HIGH immediate risk to users seeking legitimate investment opportunities. bitreem.com was registered on December 07, 2024 through NICENIC INTERNATIONAL GROUP CO., LIMITED, resolving to IP address 188.114.97.3. VirusTotal currently shows 0 of 95 security vendors flagging the domain, indicating its recent deployment and undetected malicious behavior. The domain possesses a valid SSL certificate issued by Google Trust Services, which malicious actors often exploit to appear legitimate to wary users. Domain age analysis reveals a 24-hour registration period, a common tactic among fraudulent cryptocurrency schemes designed for rapid deployment and evasion of detection systems. Recent threat intelligence indicates the domain hosts fraudulent Bitcoin investment platforms promising unrealistic returns, with infrastructure designed to harvest cryptocurrency wallet credentials and personal financial information. The low VirusTotal detection rate suggests this phishing campaign remains in its early propagation phase. Current status: bitreem.com is an ACTIVE phishing domain with no current blocklist entries despite zero VirusTotal detections. The domain employs HTTPS encryption and legitimate registrar services to enhance credibility. Users should immediately cease all interactions with bitreem.com, including refraining from clicking any links or entering personal or financial information. Security teams should implement network-level blocking of domain and IP address 188.114.97.3 to prevent access to this fraudulent cryptocurrency scam. Immediate reporting to cybersecurity platforms such as VirusTotal, PhishTank, and relevant financial fraud authorities is recommended to accelerate detection and takedown efforts. Businesses should update firewall rules and security awareness training to specifically address cryptocurrency-related phishing attacks, as bitreem.com demonstrates evolving tactics leveraging timely financial themes to lure victims.
Запись отправленного сообщения
Снимок отправленных доказательств
- Отправлено
- Записи журнала
- 1
- ID дела
PD-20260327-88D9F2- Заголовок сохранённой страницы
- Secure Global Crypto Exchange | Bitreem.com
- PDF-файл
- PDF с доказательствами
Правовое основание
Полный текст доказательств
Policy Violations: “Services may be used only for lawful purposes… fraud, abuse and illegal activity prohibited. Violations may result in immediate suspension.” + dedicated abuse handling and takedown
Applicable Laws: Crimes Ordinance Cap.200 (Fraud), Theft Ordinance Cap.210 §16A (fraud by deception), Personal Data (Privacy) Ordinance Cap.486
Данные сетевой безопасности Registrar context
Процесс реагирования на угрозы
Проверка по блок-листам
Источников: 10 · синхронизировано 09.08.2026
Сохранённые доказательства результата
Результат и атрибуция блокировки
- Результат
held- Причина
registrar_client_hold- Участник
- NICENIC INTERNATIONAL GROUP CO., LIMITED
- Механизм
client_hold- Уверенность
- 95%
Действие регистратора
NICENIC INTERNATIONAL GROUP CO., LIMITED IANA 3765
Доказательства атрибуции:
Оценка времени недоступности
Диапазон погрешности: ±2517.34 h Точность времени:very_low Хронология обнаружения
Сохранённые наблюдения в хронологическом порядке.
-
Доступность
Доступность: впервые отмечено как dns_inactive
f93a11f87e4d -
Доступность
Доступность: dns_inactive → unknown
adeb22973f6c -
Доступность
Доступность: unknown → dns_inactive
38181f0d7434 -
Доступность
Доступность: dns_inactive → held
4c1c10f8a90d -
Доступность
Доступность: held → dns_inactive
f52d526b76a1 -
Доступность
Доступность: dns_inactive → unknown
aaa561a8bc74 -
Доступность
Доступность: unknown → held
6a393977dd43 -
Доступность
Доступность: held → unknown
e6f74d08c80f -
Доступность
Доступность: unknown → dns_inactive
6dfe9145995c -
Доступность
Доступность: dns_inactive → held
138419e257f6
Показать все (6)
-
Доступность
Доступность: held → dns_inactive
641ed81dc4d5 -
Доступность
Доступность: dns_inactive → unknown
60eb69b867d0 -
Доступность
Доступность: unknown → held
22f10441b8e3 -
Доступность
Доступность: held → unknown
8db10b7c267d -
Доступность
Доступность: unknown → dns_inactive
d0b7046e8c2f -
Доступность
Доступность: dns_inactive → held
de5fc4b3192e
Сохранённый снимок
Аналитика доменов
Технические деталиDNS, SAN в протоколе SSL, временные метки
ICANN OVERSIGHT
Аккредитация и контекст RAA
Аккредитация и контекст RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Криминалистическая аналитика
Анализ VirusTotal
Анализ производительности сайта
Google PageSpeed Insights — mobile performance audit of bitreem.com · checked Mar 27, 2026
Повлиял ли на вас этот сайт?
Если вы ввели учетные данные, личную или платежную информацию или загрузили файл с этого домена, примите немедленные меры. Ниже приведены ресурсы, которые помогут вам сообщить об инциденте и защитить себя.
Сообщите об этом в местные органы власти
Выберите свою страну, чтобы получить официальные контакты по киберпреступности или создать проект жалобы →.
Проверить любой домен
Анализ угроз с использованием сохраненного черного списка, WHOIS, DNS и общедоступных доказательств сканирования.
Сканировать сейчасСообщить о фишинге
Добавляйте подозрительные домены в нашу базу данных угроз — защищайте сообщество
СообщитьПоток оперативных данных об угрозах
Недавние сообщения о фишинге и наблюдаемые изменения доступности
ОтслеживатьБудьте в курсе событий, берегите себя
Отслеживайте актуальные угрозы или оспорьте эту запись, если считаете, что это ложное срабатывание