bybit[.]internalpayservice[.]com
“How Does Bybit Internal Pay Service Work? | Bybit Blog”
bybit.internalpayservice.com — Контент недоступен. Олицетворение бренда: Bybit; Тип мошенничества: Crypto Scam. Сводка доказательств: VirusTotal 6/95 (alphaMountain.ai, CRDF, Emsisoft, Fortinet, Netcraft); PhishDestroy score 68/100. Регистратор: Dynadot.
Подробный анализ PhishDestroy AI ниже оставлен на английском, чтобы сохранить исходную криминалистическую запись.
The domain bybit.internalpayservice.com was registered through Dynadot LLC on 21 February 2026 and resolves to the IPv4 address 198.251.89.220, which is announced by AS53667 FranTech Solutions and geolocated to the United States. The authoritative name servers are ns27.asurahosting.com and ns28.asurahosting.com. The site presents a page titled “How Does Bybit Internal Pay Service Work? | Bybit Blog”, which aligns with a brand‑impersonation campaign targeting Bybit users. Security telemetry shows the domain is classified as a crypto‑scam and has been blocked by PhishDestroy; it also appears on a single external blocklist.
VirusTotal scans have returned 6 detections out of 95 AV engines, indicating partial consensus among vendors that the domain is malicious. The web server employs LiteSpeed, the Smartsupp chat widget, and supports HTTP/3. An SSL certificate identified as “R12” is present, but the certificate details have not been released publicly. As of the report date (24 July 2026) the site is taken offline, which may be temporary or a takedown response. Current analysis confirms that the domain mimics official Bybit branding in its title and likely aims to harvest cryptocurrency credentials or payments, but the exact payload or credential‑capture mechanism has not been observed.
Investigators lack access to the full page content and any associated phishing forms, so the full attack vector remains uncertain. Defenders should continue to block the domain at network perimeter and DNS layers, monitor the associated IP address and name server infrastructure for any re‑activation, and add the domain to internal threat‑intel feeds. Additional scrutiny of traffic to 198.251.89.220, especially HTTP/3 connections using LiteSpeed, is advised. Organizations using Bybit services should alert users to the existence of this impersonation attempt and reinforce legitimate communication channels.
Процесс реагирования на угрозы
Статус в публичных блок-листах
Сохранённый снимок
Аналитика доменов
Технические сведенияDNS, SAN в протоколе SSL, временные метки
ICANN OVERSIGHT
Registration: internalpayservice.com
Аккредитация и контекст RAA
Аккредитация и контекст RAA
Registrar accreditation and DNS abuse obligations
For the registrable domain internalpayservice.com behind this subdomain, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Технологии · 3 identified
High-performance web server compatible with Apache configurations.
Live chat and visitor recording tool for customer support.
Third major version of HTTP protocol, built on QUIC for faster, more reliable connections.
Анализ VirusTotal
Доказательства и внешние отчеты
Повлиял ли на вас этот сайт?
Если вы ввели учетные данные, личную или платежную информацию или загрузили файл с этого домена, примите немедленные меры. Ниже приведены ресурсы, которые помогут вам сообщить об инциденте и защитить себя.
Сообщите об этом в местные органы власти
Выберите свою страну, чтобы получить официальные контакты по киберпреступности или создать проект жалобы →.
Проверить любой домен
Анализ угроз с использованием сохраненного черного списка, WHOIS, DNS и общедоступных доказательств сканирования.
Сканировать сейчасСообщить о фишинге
Добавляйте подозрительные домены в нашу базу данных угроз — защищайте сообщество
СообщитьПоток оперативных данных об угрозах
Недавние сообщения о фишинге и наблюдаемые изменения доступности
ОтслеживатьБудьте в курсе событий, берегите себя
Отслеживайте актуальные угрозы или оспорьте эту запись, если считаете, что это ложное срабатывание