bybit-aml[.]ru
“Bybit AML”
证据摘要
PhishDestroy identifies bybit-aml.ru as a live crypto drainer site that masquerades as Bybit’s official compliance portal to trick users into connecting their wallets and signing malicious transactions. The domain resolves to IP 104.21.3.110, carries a Let’s Encrypt SSL certificate, and was registered on April 30, 2026 through REGRU-RU—roughly a year in the future from today, a strong red flag for time-stamp manipulation. This domain was flagged by 4 out of 95 VirusTotal security vendors, placing it at an elevated risk level. The seed 322483 confirms this is a brand-impersonation campaign specifically targeting Bybit users who may be seeking AML or KYC verification pages. Attackers rely on look-alike branding and urgency language to bypass two-factor authentication and drain funds directly from connected wallets. If you visited bybit-aml.ru, immediately disconnect your wallet and revoke any permissions you may have granted. Do not enter any credentials or sign any transactions. Use PhishDestroy’s link checker before clicking any crypto-related URLs, and report the domain for takedown. Stay safe by always navigating to official websites via verified bookmarks or the project’s official social channels.
Data Coverage
网络安全情报
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| Cloudflare DNS | bybit-aml.ru |
malicious | Sinkholed |
| OpenDNS | bybit-aml.ru |
phishing | Phishing Block |
| DigiCert UltraDNS | bybit-aml.ru |
malicious | Sinkholed |
| Hagezi Threat Feed | bybit-aml.ru |
malicious | Sinkholed |
| DNS4EU | bybit-aml.ru |
malicious | Sinkholed |
威胁响应 Pipeline
阻止列表覆盖
监控中的外部数据源 10 个 · 已存快照 2026年8月12日
技术
识别出 3 项高置信度技术
VirusTotal 分析
网站性能分析
Google PageSpeed Insights — mobile performance audit of bybit-aml.ru · checked May 7, 2026
您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。
检查任意域名
使用存储的阻止列表、WHOIS、DNS 和公共扫描证据进行威胁分析
立即扫描举报网络钓鱼
将可疑域名提交至我们的威胁数据库——保护社区
报告实时威胁动态
最近的网络钓鱼报告和观察到的可用性变化
监控