Zum Sicherheitsbericht springen
Checked 09.08.2026 Ref 7917F390

MALICIOUS — CRITICAL

frozbet[.]com

18 of 93 security engines flagged the domain; the latest stored check returned HTTP 502.

100/100 evidence score · Critical
VirusTotal
18/93
Blocklists
No stored match
Verfügbarkeit
Inhalt nicht verfügbar · HTTP 502
Report / Add Evidence Appeal this listing
2026-01-24 12:03 UTCInhalt nicht verfügbar · HTTP 502

Do not enter credentials, seed phrases, payment details, or personal information on this domain.

⚠️
Diese Domain wurde als bösartig markiert.
Sicherheits-Engines melden eine Entdeckung: 18. Seien Sie äußerst vorsichtig – Geben Sie keine Anmeldeinformationen oder persönlichen Daten ein.
Jump to section
Berichtsübersicht

frozbet.com — Inhalt nicht verfügbar (HTTP 502). Markenidentität: Genericcrypto; Betrugstyp: Crypto Scam. Zusammenfassung der Beweislage: VirusTotal 18/93 (ADMINUSLabs, alphaMountain.ai, BitDefender, Cluster25, CRDF); URLQuery 100 det.; URLScan malicious verdict; Spamhaus DBL_PHISH; PhishDestroy score 100/100. Registrar: NiceNIC.

Die ausführliche Analyse von PhishDestroy AI bleibt auf Englisch, damit der ursprüngliche forensische Bericht unverändert bleibt.

Evidence Digest

Ref 7917F390

frozbet.com is classified critical with an evidence score of 100/100. 18 of 93 security engines flagged the domain. Registration metadata recorded via NiceNIC International Group Co., Limited, hosted on 188.114.97.3 (Cloudflare, Inc., US). The latest stored check on 9 Aug 2026 returned HTTP 502 and includes a capture. 5 outgoing abuse reports are recorded, most recently on 31 Jan 2026.

Stored generated summary (templated)mistral · 25.06.2026

Retained for the record. This text repeats stored detection facts and is not presented as authored analysis.

This domain, frozbet.com, is confirmed to operate as a brand impersonation phishing site targeting users of cryptocurrency-based gambling platforms. Analysis of the site’s content and metadata reveals an attempt to mimic legitimate crypto casino services, with the page title explicitly stating 'Frozbet: Most Popular Online Crypto Casino Based on Blockchain.' The domain does not deploy a known cryptocurrency drainer kit but instead focuses on deceiving users into engaging with fraudulent gambling services, likely to harvest credentials or facilitate unauthorized transactions. Infrastructure analysis reveals critical technical indicators associated with this threat. The domain was registered on February 21, 2026, through NiceNIC International Group Co., Limited, a registrar frequently observed in phishing campaigns. It resolves to the IP address 188.114.97.3, hosted on AS13335 (Cloudflare, Inc.), a network commonly leveraged to obfuscate malicious infrastructure. At the time of assessment, the domain appears on a single security blocklist, while VirusTotal reports 18 out of 95 security vendors flagging it as malicious. Notably, the domain lacks an SSL certificate, further reducing its legitimacy and increasing the risk of interception during user interactions. As of the latest assessment, frozbet.com has been taken offline, likely in response to detection and blocking by security mechanisms. However, the elevated risk level persists due to the domain’s recent registration and association with a registrar known for hosting fraudulent sites. Users are advised to treat any prior interactions with this domain as compromised and to monitor accounts linked to cryptocurrency or gambling services for unauthorized activity. Organizations should update blocklists to include this domain and its associated IP to prevent future access attempts.

VirusTotal
VirusTotal
18 det.
URLQuery
URLQuery
100 det.
URLScan
URLScan
Gridinsoft
1/100
ScamAdviser
Scamadviser
1/100
TLS-Zertifikat
WE1
Beobachteter Status
Inhalt nicht verfügbar 502
PhishDestroy
DestroyList
Gelistet
Reports Sent
5
Datenabdeckung14 recorded checks
VirusTotal 18 / 93 URLQuery 100 det. PhishStats checked — no match recorded OTX no community references CF-Radar scan completed URLScan capture gespeicherter Bericht URLScan verdict malicious DNS-Sperren nicht geprüft TLS valid certificate, 43d WHOIS not parsed Screenshot 2 captures · 2 sources Weiterleitungskette nicht untersucht Gridinsoft 1/100 Scamadviser 1/100
Sicherheitssignale
SA Scamadviser Warnings 1/100
The website's owner is hiding his identity on WHOIS using a paid service This website does not have many visitors Several spammers and scammers use the same registrar We detected cryptocurrency services which can be high risk This website has only been registered recently. DNSFilter reported this website as malicious in the last 30 days
According to the SSL check the certificate is valid
GS Gridinsoft Analysis 1 / 100
Hosting SSL Certificate Scam - High Risk Amazon Phishing - High Risk Cryptocurrency Financial Service Registration Form Casino
Erkenntnisse zur Netzwerksicherheit Registrar context
Registrar context NiceNIC
Stored registration data identifies NICENIC INTERNATIONAL GROUP CO., LIMITED (IANA 3765) as the registrar. PhishDestroy maintains separate NiceNIC abuse-report research; registrar association is contextual and is not an independent detection for this domain.
NiceNIC Verdict Full Investigation

Pipeline zur Reaktion auf Sicherheitsbedrohungen

Entdeckung
Checks
Reports
Verfügbarkeit
22/22
Initial Abuse Report (#1)
Sent to 1 abuse contact at NiceNIC International Group Co., Limited with forensic evidence
support@nicenic.net
31.01.2026
Follow-up Report #2
Escalation #2 sent to 1 recipient — follow-up record after a previous report
support@nicenic.net
08.02.2026
ICANN Escalation #3
Escalation #3 sent to 3 recipients including ICANN Compliance — follow-up record after multiple previous reports
support@nicenic.netabuse@verisign-grs.comcompliance@icann.org
14.02.2026
ICANN Escalation #4
Escalation #4 sent to 3 recipients including ICANN Compliance — follow-up record after multiple previous reports
abuse@nicenic.netabuse@verisign-grs.comcompliance@icann.org
03.03.2026
ICANN Escalation #5
Escalation #5 sent to 3 recipients including ICANN Compliance — follow-up record after multiple previous reports
abuse@nicenic.netabuse@verisign-grs.comcompliance@icann.org
04.03.2026
5 Reports Filed
5 report records were stored over 189 days; current observed status: Inhalt nicht verfügbar

Status der öffentlichen Sperrliste

Gespeicherte Aufnahme

Seitentitel
Frozbet: Most Popular Online Crypto Casino Based on Blockchain
TLS-Zertifikat
Valid transport encryption · Ausgestellt von WE1 · valid for 43 days

Domain-Intelligenz

Domain
URLScan Verdict Schädlich score 100 Phishing report ↗
Server / ASN cloudflare · AS13335 Cloudflare, Inc.
IP Context Cloudflare shared edge origin IP hidden Die Edge-IP-Reputation wird dieser Domäne nicht zugeordnet.
Registrar NiceNIC RU(RU) PhishDestroy Investigation
IP-Adresse 188.114.97.3 CDN
StandortUS San Francisco, US
NetzwerkAS13335 · Cloudflare, Inc.
Die Ursprungs-IP ist hinter einem CDN-Proxy verborgen. Reverse-IP-Ergebnisse für die Edge-Adresse enthalten nicht verwandte Mandanten; Um den Ursprung zu finden, sind passive DNS- oder Zertifikatstransparenzdaten erforderlich.
HTTP-Status502 Error
Zeit bis zur ersten Nichtverfügbarkeit 28 days
Was wir zählen Verstrichene Zeit von der ersten gespeicherten Missbrauchsmeldung bis zur ersten Feststellung, dass der Inhalt nicht verfügbar war. Damit ist die Ursache nicht geklärt.
Minimum notice count 5 is the number of stored outgoing report records for this domain. It does not by itself prove acknowledgement or action by a recipient.
Was jeder Bericht enthält Gespeicherte Ausgangsberichtsaufzeichnungen können auf zu diesem Zeitpunkt verfügbare Beweise verweisen, wie z. B. Urteile von Anbietern, Registrierungsdaten, Hosting-Details, Klassifizierungen oder Screenshots. Diese Seite lässt keine Rückschlüsse auf die genaue zugestellte Nutzlast, den Empfang, die Bestätigung oder die Aktion eines Empfängers zu.
ICANN RAA §3.18 The history below lists stored escalation records and timestamps. It does not by itself establish receipt, acknowledgement, compliance, or enforcement by any recipient.
Technische DetailsDNS, SSL-SANs, Zeitstempel
Erstmals entdeckt24.01.2026
DOM Analysisanalyzed 29.07.2026score 0/100
IoC Extractionscanned 02.08.20260 wallet · 0 Telegram IoCs
Submitted URLhttps://frozbet.com/
Nameservercullen.ns.cloudflare.compriscilla.ns.cloudflare.com
TLS Observationvalid from 12.01.2026scanned 15.03.2026
Case ID
ICANN OVERSIGHT

Akkreditierung und RAA-Kontext

Registrar accreditation and DNS abuse obligations

For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.

Accreditation is a contract, not a safety certification.

RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.

Accountability draft Nichts wird automatisch gesendet.

Latest Classified Outcome 2026-08-09 03:55:06 UTC

Primary outcome Registration hold observed reason: Registrar clientHold 95% confidence
Attribution NICENIC INTERNATIONAL GROUP CO., LIMITED mechanism: Registrar clientHold source: Rdap Status Collector
Evidence layers Availability: DNS inactive Content: Unreachable DNS: NXDOMAIN Registration: Registrar clientHold
Latest HTTP observation Unbekannt Origin unreachable Http 5xx 20% 2026-08-09 01:35:10 UTC
RDAP registration Registrar clientHold NICENIC INTERNATIONAL GROUP CO., LIMITED · IANA 3765 RDAP HTTP 200 source: Rdap Status Collector clientDeleteProhibitedclientHoldclientTransferProhibited expires 2027-01-12 09:35:43 UTC checked 2026-08-09 03:55:06 UTC
Registrar action marker verified clientHold marker NICENIC INTERNATIONAL GROUP CO., LIMITED · IANA 3765 causal link to our report not established
Observed timeline last reachable: 2026-02-14 16:33:42 UTC current episode first observed: 2026-08-05 01:45:38 UTC observed RIP window: 2026-02-14 16:33:42 UTC → 2026-08-05 01:45:38 UTC · 4,113.20h midpoint estimate ≈ 2026-05-11 09:09:40 UTC · precision very low · basis bounded
Availability, content, DNS and registration are independent evidence layers. NXDOMAIN, an unreachable origin or missing content alone does not prove registrar action. A registrar or provider is credited only when a direct technical marker identifies that actor. Report causality is shown separately.
Verlauf der Missbrauchsmeldungen · 5 stored reports over 32 days · click to expand
This timeline is built from stored outgoing report records. It documents timestamps and listed recipients, but does not by itself prove delivery, acknowledgement, or recipient action.
5 abuse reports filed over 189 days — latest observed status: Inhalt nicht verfügbar
The records name NiceNIC International Group Co., Limited as a recipient or subject. ICANN Compliance appears in the recipient field for at least one record.
5
reports
189
days
ICANN CC
  1. Report #1 Jan 31, 2026 · 20:11 UTC
    Phishing Abuse Report: frozbet[.]com
    support@nicenic.net
  2. Report #2 Escalation 190h still active Feb 8, 2026 · 18:23 UTC
    ESCALATION #2 (190h active): Phishing - frozbet[.]com
    support@nicenic.net
  3. Report #3 ICANN CC 337h still active Feb 14, 2026 · 21:32 UTC
    ESCALATION #3 (337h active): Phishing - frozbet[.]com
    support@nicenic.net abuse@verisign-grs.com compliance@icann.org
  4. Report #4 ICANN CC 726h still active Mar 3, 2026 · 02:50 UTC
    ESCALATION #4 (726h active): Phishing - frozbet[.]com
    abuse@nicenic.net abuse@verisign-grs.com compliance@icann.org
  5. Report #5 ICANN CC 762h still active Mar 4, 2026 · 14:56 UTC
    ESCALATION #5 (762h active): Phishing - frozbet[.]com
    abuse@nicenic.net abuse@verisign-grs.com compliance@icann.org
Record scope: the timeline documents outgoing records stored by PhishDestroy. Delivery, acknowledgement, and subsequent action require separate recipient or infrastructure evidence.
Casino / Gambling License Verification
Unverified gambling license
This domain markets casino/gambling services. Scam casinos routinely display fake Curaçao, MGA, or Kahnawake license badges that don’t exist in the real registries. Always verify the license number against the official regulator database before depositing. If the site shows a seal but no clickable registry link — or the linked registry page doesn’t exist — treat it as fraudulent.
Curaçao eGaming (official) Malta Gaming Authority UK Gambling Commission PA Gaming Control Kahnawake Gaming Gibraltar Gambling
Diese Domain melden Reichen Sie Beweismaterial ein und helfen Sie mit, andere zu schützen

VirusTotal-Analyse

18 / 93 Sicherheitsanbieter haben diese Domain markiert
View on VT
Last analyzed
ADMINUSLabs
alphaMountain.ai
BitDefender
Cluster25
CRDF
CyRadar
ESET
Forcepoint ThreatSeeker
Fortinet
G-Data
Gridinsoft
Kaspersky
Lionic
Netcraft
Seclookup
SOCRadar
Sophos
VIPRE

Archivierte Beweise

Wayback Machine Snapshot
Zur Beweisüberprüfung steht ein historischer Schnappschuss zur Verfügung
View Archive
Nachweise und externe BerichteIndependent lookups and source reports
Victim safety and official reportingImmediate actions and verified reporting channels
If credentials were compromised, report immediately. Do not engage with recovery scammers.

Wenn Sie Kontoanmeldeinformationen, persönliche oder Zahlungsinformationen eingegeben oder eine Datei von dieser Domain heruntergeladen haben, ergreifen Sie sofort Maßnahmen. Nachfolgend finden Sie Ressourcen, die Ihnen helfen, den Vorfall zu melden und sich zu schützen.

Europol
Finden Sie den offiziellen Meldekanal für Ihr EU-Land
National police directory
Vorsicht vor Betrügern, die mit der Rückforderung von Geldern locken! Kriminelle nehmen unter Umständen erneut Kontakt zu Opfern auf und geben dabei vor, Ermittler, Anwälte oder Beitreibungsbeamte zu sein. Zahlen Sie keine Vorabgebühren und geben Sie keine Anmeldeinformationen weiter. Erfahren Sie mehr über Betrug im Zusammenhang mit Wiederaufbaumaßnahmen →

Melden Sie sich bei Ihren örtlichen Behörden

Wählen Sie Ihr Land aus, um Offizielle Kontakte im Bereich Cyberkriminalität oder einen Beschwerdeentwurf erstellen → zu erhalten.

97-Länder-Verzeichnis
KI-gestützter Entwurf – Vorfalldetails werden vom KI-Anbieter verarbeitet Überprüfen Sie es und reichen Sie es selbst ein
Diesen Bericht einbettenRead-only HTML widget
HTML · IFRAME

Diesen Bericht einbetten

Teilen Sie diese Bedrohungsinformationen auf Ihrer Website oder in Ihrem Blog

embed.html
<iframe
  src="https://phishdestroy.io/de/embed/domain/frozbet.com"
  title="PhishDestroy threat report for frozbet.com"
  width="100%" height="320"
  loading="lazy"
  referrerpolicy="no-referrer"
  sandbox="allow-same-origin allow-popups allow-popups-to-escape-sandbox"
  style="border:0;border-radius:12px;max-width:100%"
></iframe>

Ein sehr aufrichtiges Dankesschreiben

Generator für satirische Entwürfe

Empfänger
Gebührenkontext

Satirischer Entwurf. Die Gebührenangaben sind Schätzungen; eine genaue Zuordnung zu dieser Domain wird nicht behauptet.