MALICIOUS — CRITICAL
bit-pay.co 网络钓鱼与安全检查
bit-pay[.]
The domain bit-pay.co is currently active and has been identified as a high‑risk brand‑impersonation site.
- VirusTotal
- 11/91
- Blocklists
- 2 · MetaMask, SEAL
- 可用性
- 最后已知的活跃状态 · HTTP 200
Do not enter credentials, seed phrases, payment details, or personal information on this domain.
Jump to section
bit-pay.co — 最后已知的活跃状态 (HTTP 200). 品牌冒充:Across; 诈骗类型:Crypto Scam. 证据摘要: VirusTotal 11/91 (ADMINUSLabs, alphaMountain.ai, BitDefender, Chong Lua Dao, CRDF); 2 external blocklist matches (MetaMask, SEAL); PhishDestroy score 93/100.
为保留原始取证记录,下方的 PhishDestroy AI 详细分析仍使用英文。
Evidence Analysis
The domain bit-pay.co is currently active and has been identified as a high‑risk brand‑impersonation site. It presents the page title “BitPay: The Best Crypto App to Pay with Crypto + Accept Payments |”, indicating a cryptocurrency focus. The site is listed on three security blocklists and has been flagged by one of ninety‑five VirusTotal scanners. Its SSL certificate is issued by Let’s Encrypt (E7), and the HTTP response returns status code 200.
Infrastructure analysis shows the domain resolves to IP address 104.18.78.118, which belongs to Cloudflare, Inc. (AS13335) and is geolocated in the United States. The authoritative nameservers are a.share-dns.com and b.share-dns.net, both typical of shared DNS services. The domain was registered on March 11, 2026, and remains active as of the report date.
Threat intelligence sources reinforce the malicious assessment. The domain appears in twenty‑two AlienVault OTX pulses and is present on three security blocklists. It has been explicitly blocked by PhishDestroy, SEAL, and additional security solutions. Gridinsoft assigns a trust score of zero out of one hundred, and the site is categorized as a cryptocurrency scam. The impersonated brand is listed as “across,” though the page content has not been publicly reviewed to confirm the extent of brand misuse.
Defenders should add bit-pay.co to network‑level deny lists and configure web filters to block both HTTP and HTTPS traffic to the resolved IP address. Continuous monitoring of DNS queries for the associated nameservers is advised, as well as periodic re‑scanning with multi‑engine services to detect any changes in payload or hosting. Incident response teams should treat any credential or payment data submitted to this domain as compromised and advise affected users to change authentication details immediately.
Stored source results
Recorded verdicts and infrastructure observations for this domain.
数据覆盖范围12 recorded checks
威胁响应 Pipeline
公共封禁名单状态
VirusTotal 分析
证据与外部报告Independent lookups and source reports
Victim safety and official reportingImmediate actions and verified reporting channels
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。