Security Scan Report: mail.bybitsupport.org

Site favicon
Submitted: Sep 14, 2026, 8:43:02 PMCompleted: Sep 14, 2026, 8:44:20 PMpubliccompleted

Summary

This website contacted 1 IP in 1 country across 1 domain to perform 2 HTTP transactions. The main domain is mail.bybitsupport.org and was registered 2 weeks ago.

Submitted URL: https://mail.bybitsupport.org

AI Security Verdict

Low Risk

Confidence: 68%

3
Risk Score

Brand-new, unranked domain whose name mimics Bybit support, hosting a Roundcube webmail credential login. No malware or IoC hits, but the look-alike hostname plus fresh registration makes it unsafe for entering credentials.

Risk Factors
Domain registered 18 days ago and unranked
Hostname impersonates a well-known crypto exchange's support brand
Credential entry page (username/password) on a young, non-official look-alike domain
Safety Factors
No Indicators of Compromise matches
No JavaScript YARA malware patterns
No network IDS alerts
No cross-origin form submission or credential exfiltration detected
Login form posts same-origin as standard Roundcube software
Verdict cited a credential/login form, but DOM analysis found no password field (real or disguised) or payment field, and no other hard signal — credential-phishing framing unsupported; risk adjusted from 7 to 3
Domain age information unavailable

Details

Page Title

Roundcube Webmail :: Welcome to Roundcube Webmail

Scan Type

public

Language

🇺🇸

English

(80% confidence)

Category

documentation technical

(45%)

Domain Information

The domain name 'mail.bybitsupport.org' uses the non-profit oriented generic top-level domain (.org); it also runs on subdomain 'mail'. The registrable portion 'bybitsupport' spans 12 characters with three vowels and nine consonants. Tokenizing the label suggests 3 words: by, bit, support. Expect three characters per word on average. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://mail.bybitsupport.org

Page Load Overview

75.45s
Total Load Time
2
HTTP Requests
1
Domains
N/A
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

Language Code:en
Detection Confidence:80%
Script Type:Latin
HTML Lang Attribute:en
Text Length:238 chars
Detector Agreement:100%

Website Classification

Primary Category

documentation technical45% confidence
Type: webapp
Method: ml+structural

All Detected Categories

documentation technical
45%
phishing scam
42%
technology software
41%
news media journalism
36%
adult content
36%

Detected Features

Login Form

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
2188.127.225.238Moscow, Moscow, Russia
AS56694LLC Smart Ape
01--

Page Statistics

0
Requests
0
Unique Domains
0.0 KB
Total Size

Detected Technologies5

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T18E1148B3AC00883F1571011D9849F69CE4ED587991757D10F4AF173D1DF8FAD84AE991

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

12:hRZrYfNg7YDnyLmgd7ZV4VzxEGj0h2PmgLcAuPmfnrPmZPX6mzqx9QFOvmRVh+Bt:hRZsGkDnOmWZKJDLcA9edmSqmRVkByG

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:974:AEAEAAAAgAAAAAAAAAIIIBAAAIAAAAAAAAABAAEAAAAAABAaAAAABIAAAAIAAAAQIAAAAgEAIACAAAAQAAABAAAAAACEEkAg

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:ffe7e7e7ffffffff
Perceptual Hash:b333cccc64339999
Difference Hash:00080c0c00000000
Wavelet Hash:ffe7e7e700000000
Color Hash:#5356ac

Other Hashes

Crop Resistant:00080c0c00000000

Scan History

Scan history not available

Unable to load historical scan data