# PhishDestroy threat dossier — kfrl.com ================================================================ Fetched: 2026-07-22 03:34:54 UTC Canonical: https://phishdestroy.io/domain/kfrl.com/ ## VERDICT ---------------------------------------------------------------- CRITICAL THREAT — DO NOT VISIT Composite threat score: 100/100 (PhishDestroy scoring — see methodology below) Scam classification: Crypto Drainer ## DETECTION EVIDENCE ---------------------------------------------------------------- VirusTotal: 1/91 security vendors flagged this domain Flagging vendors: Gridinsoft AlienVault OTX: 1 pulses (threat-intel feed mentions) Public blocklists: listed on 3 independent blocklists ## INFRASTRUCTURE ---------------------------------------------------------------- IP address: 23.225.114.171 (US, Los Angeles) ASN: ASAS40065 CNSERVERS - CNSERVERS LLC, US Hosting org: AS40065 CNSERVERS LLC Registrar: West263 International Limited Nameservers: ns1.myhostadmin.net, ns2.myhostadmin.net, ns3.myhostadmin.net, ns4.myhostadmin.net, ns5.myhostadmin.net, ns6.myhostadmin.net Registered: 2004-07-23 Expires: 2026-07-23 Page title: 比特派钱包下载官网-比特派官方下载-比特派钱包app官方下载最新版本-Bitpie全球多链数字钱包 HTTP response: 200 ## TLS CERTIFICATE ---------------------------------------------------------------- Issuer: TrustAsia Technologies, Inc. / LiteSSL RSA CA 2025 Expires: 2026-09-06 Status: INVALID chain Fingerprint: f0c00dd1492e1cd163f010f38cc0420a211a9d2ec6e94e6db04494d614f67dd8 Subject Alternative Names (related infrastructure — often same operator): - m.kfrl.com - www.kfrl.com ## ABUSE-REPORT HISTORY (evidence of registrar non-response) ---------------------------------------------------------------- Status: pending notification queue. No abuse reports filed yet — this domain is waiting for the next cycle of our automated abuse-reporter. ## TIMELINE ---------------------------------------------------------------- Domain registered: 2004-07-23 (per WHOIS / CT — may reflect a renewal or transfer date, not first-ever registration) First detected: 2026-07-06 16:41:38 UTC (by PhishDestroy tracker) Last verified: 2026-07-22 04:20:23 UTC Current status: ACTIVE / observable ## EXTERNAL CORROBORATION (third-party evidence) ---------------------------------------------------------------- URLScan.io: https://urlscan.io/result/019f37df-4535-74d9-8f71-7b8d9ce53118/ Wayback Machine: https://web.archive.org/web/*/kfrl.com crt.sh CT logs: https://crt.sh/?q=%25.kfrl.com Google transparency: https://transparencyreport.google.com/safe-browsing/search?url=kfrl.com AlienVault OTX: https://otx.alienvault.com/indicator/domain/kfrl.com URLhaus: https://urlhaus.abuse.ch/host/kfrl.com/ ## ANALYST NARRATIVE ---------------------------------------------------------------- [Generated: 2026-07-06 16:46:40 UTC — narrative may predate facts above. Treat fields in TIMELINE / DETECTION EVIDENCE / INFRASTRUCTURE as authoritative if they differ from the prose below.] kfrl.com — Crypto Drainer Phishing Investigation Report This domain, kfrl.com, is under investigation for phishing activity that appears to be targeting users of Bitpie, a global multi-chain digital wallet. The site presents itself as the official Bitpie wallet download page, but it is suspected of being a fraudulent site designed to trick users into downloading a malicious version of the Bitpie wallet app, potentially leading to the theft of cryptocurrency and personal information. Analysis indicates that the domain kfrl.com was created on July 23, 2004, which is an unusually long time for a domain to remain active without raising red flags. The domain is currently registered through West263 International Limited, and it resolves to the IP address 23.225.114.171. The SSL certificate is issued by TrustAsia Technologies, Inc. Despite its longevity, the domain has not been flagged by VirusTotal, with 0 out of 95 detections. This lack of detection might suggest that the domain is relatively new to malicious activity or that the threat actors are using sophisticated techniques to evade detection. If a user has visited kfrl.com, they should immediately check their Bitpie wallet and any other digital wallets for unauthorized transactions. Users should also update their passwords and enable two-factor authentication if not already done. It is recommended to monitor financial accounts for any signs of fraudulent activity. Reporting the incident to Bitpie's support team and the relevant authorities can help mitigate the potential damage and prevent others from falling victim to this scam. ## EVIDENCE HASHES ---------------------------------------------------------------- TLS cert SHA-256: f0c00dd1492e1cd163f010f38cc0420a211a9d2ec6e94e6db04494d614f67dd8 ## SCORING METHODOLOGY ---------------------------------------------------------------- Composite score is NOT derived from VirusTotal alone. PhishDestroy aggregates: - VirusTotal positive ratio - Public blocklist consensus (MetaMask, ScamSniffer, OpenPhish, PhishTank, URLhaus, CryptoFirewall, SEAL, Polkadot, Enkrypt, Phishunt, DiscordPhishing, PhishingDB) - Cloaking detection (HTTP 666 or rendering delta between bot and real visitor) - DNS-filter consensus (Quad9, CleanBrowsing, NextDNS, AdGuard, Cloudflare, etc.) - AlienVault OTX pulses + Cloudflare Radar + Google Safe Browsing - URLScan / URLQuery verdicts - Brand-impersonation heuristics (DOM analysis of forms, logos, wording) - Known phishing-kit fingerprinting (favicon hash, JS obfuscation signatures) - Wallet-drainer family classification (Angel, MS, Rainbow, Pink, Inferno, ...) - Free-TLS vs paid-cert ratio (throwaway infrastructure signal) - Registrar/hosting abuse history (this registrar's track record) - Human researcher sign-off (operator takedown team) A domain present in our database is ALREADY flagged. A low VT count by itself does NOT mean the domain is safe — new scam domains routinely show 0/95 VT for their first 7–30 days while actively draining wallets. Always cross-reference the composite score and the individual indicators above, not just VT. ## CORRECTIONS / APPEALS ---------------------------------------------------------------- Full HTML report: https://phishdestroy.io/domain/kfrl.com/ JSON API: https://api.destroy.tools/v1/check?domain=kfrl.com Appeal a flag: https://phishdestroy.io/appeals/ (responded to within 48 hours, FP rate <0.01%) Submit a report: https://t.me/PhishDestroy_bot About PhishDestroy: independent open-source threat-intelligence platform. Tracked: 187,720 domains (57,297 alive under monitoring, 128,779 confirmed takedowns/dead). Site: https://phishdestroy.io