bitwalletmarket[.]ltd
“Bitwalletmarket – welcome to Bitwalletmarket”
Сохранённое наблюдение
Зафиксированное различие заголовков
Сводка доказательств
This domain, bitwalletmarket.ltd, has been identified as a brand impersonation threat specifically targeting Google. Analysis indicates the page title, 'Bitwalletmarket – welcome to Bitwalletmarket,' mimics legitimate service nomenclature to deceive users into believing the site is associated with the targeted brand. No direct evidence of a crypto drainer kit was observed, but the domain's infrastructure and design suggest intent to harvest credentials or distribute malicious payloads under the guise of a trusted entity. The threat type aligns with typical brand abuse tactics, where attackers exploit familiarity to lower user defenses. Infrastructure analysis reveals the domain was registered through Global Domain Group LLC on November 19, 2025, and resolves to the IP address 198.12.80.250. Detection metrics show 13 out of 95 security vendors on VirusTotal flagged the domain as malicious, while it appears on a single security blocklist, specifically PhishDestroy. The domain's SSL certificate is issued by Let's Encrypt, a common tactic to lend superficial legitimacy. Gridinsoft assigns a trust score of 0/100, reinforcing the high-risk classification. No entries were found in Google Safe Browsing at the time of analysis, though this does not preclude prior or future listings. The domain is currently offline, likely due to takedown actions or infrastructure adjustments by the threat actor. However, the risk remains elevated due to the domain's recent registration and the potential for reactivation under altered parameters. Users and organizations are advised to block the domain and its associated IP at the network level. Monitoring for similar domains registered through the same registrar or resolving to the same IP range is recommended to preemptively mitigate related threats. Vigilance is particularly warranted for users who may have interacted with the domain prior to its takedown, as credential exposure or secondary infections cannot be ruled out.
Data Coverage
Данные сетевой безопасности
Процесс реагирования на угрозы
Проверка по блок-листам
10 внешних источников под наблюдением · снимок от 12.08.2026
10 внешних источников под наблюдением Совпадений нет
Хронология обнаружения
-
VirusTotal
2 → 1
-
VirusTotal
1 → 2
-
VirusTotal
2 → 13
Сохранённый снимок
Аналитика доменов
Технические деталиDNS, имена TLS и временные метки
ICANN OVERSIGHT
Аккредитация и контекст RAA
Аккредитация и контекст RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Анализ VirusTotal
Анализ производительности сайта
Google PageSpeed Insights — mobile performance audit of bitwalletmarket.ltd · checked Jun 27, 2026
Повлиял ли на вас этот сайт?
Если вы ввели учетные данные, личную или платежную информацию или загрузили файл с этого домена, примите немедленные меры. Ниже приведены ресурсы, которые помогут вам сообщить об инциденте и защитить себя.
Сообщите об этом в местные органы власти
Выберите свою страну, чтобы получить официальные контакты по киберпреступности или создать проект жалобы →.
Проверить любой домен
Анализ угроз с использованием сохраненного черного списка, WHOIS, DNS и общедоступных доказательств сканирования.
Сканировать сейчасСообщить о фишинге
Добавляйте подозрительные домены в нашу базу данных угроз — защищайте сообщество
СообщитьПоток оперативных данных об угрозах
Недавние сообщения о фишинге и наблюдаемые изменения доступности
ОтслеживатьБудьте в курсе событий, берегите себя
Отслеживайте актуальные угрозы или оспорьте эту запись, если считаете, что это ложное срабатывание