bybitclubin[.]my
“Bybit Digital Trading Platform”
bybitclubin.my — 未验证. 品牌冒充:Bybit; 诈骗类型:Crypto Scam. 证据摘要: VirusTotal 10/91 (ADMINUSLabs, alphaMountain.ai, BitDefender, CRDF, CyRadar); Google Safe Browsing flagged; PhishDestroy score 80/100. 注册商: Dynadot.
为保留原始取证记录,下方的 PhishDestroy AI 详细分析仍使用英文。
The domain bybitclubin.my was registered on August 01, 2025 through Dynadot LLC and is hosted on IP address 206.119.171.228, which maps to a Japanese network (AS133199 SonderCloud Limited). The authoritative nameservers ns1.dyna-ns.net and ns2.dyna-ns.net are typical of dynamically allocated DNS services and provide no additional reputation signals. No TLS certificate is presented, indicating that the site was served over plain HTTP at the time it was observed. The page title returned by the web server reads "Bybit Digital Trading Platform", aligning with the declared scam type of a crypto scam and the listed impersonation of the Bybit exchange.
Google Safe Browsing has flagged the URL for social engineering, and the domain appears on a single external blocklist maintained by PhishDestroy. VirusTotal recorded scans by 95 antivirus and URL‑reputation engines, none of which reported a detection; while this suggests the payload was not recognized by those engines, it does not constitute a safety assurance. The site is currently offline, preventing immediate interaction, but the historical evidence indicates a deliberate attempt to mislead users by leveraging the Bybit brand.
Uncertainties remain regarding the specific phishing kit or credential‑capture mechanisms employed, as no page content or source‑code has been disclosed. Defensive actions should include adding the domain to internal blocklists, monitoring for any resurgence of the same IP or nameserver pair, and correlating any inbound traffic to the Bybit brand with this indicator set. Security teams should also advise users to verify the absence of TLS and to consult official Bybit communications when encountering unsolicited crypto‑related offers, as the combination of brand‑specific page title, social‑engineering flag, and lack of encryption are consistent with known impersonation campaigns.
威胁响应 Pipeline
公共封禁名单状态
VirusTotal 分析
存档证据
证据与外部报告
您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。