bitfrost[.]live
“Bifrost Wallet - Self-custody, multi-chain crypto wallet for DeFi, NFTs and Web3”
साक्ष्य सारांश
bitfrost.live has been confirmed as an active generic phishing site. This domain poses a high risk by masquerading as a cryptocurrency wallet to harvest user credentials and private keys. The campaign is currently undetected by security vendors, with 0 detections on VirusTotal as of the latest scan, and has not yet been added to public blocklists. Given the domain’s recent creation on February 20, 2026, and the use of a Let’s Encrypt SSL certificate, attackers are leveraging trusted infrastructure to lend credibility to their fraudulent site. The infrastructure is hosted at IP 187.77.176.43, which has no established reputation, and is registered through NameSilo, LLC, a registrar commonly abused for short-lived malicious domains. The combination of low detection rates, new registration, and plausible infrastructure suggests this is an early-stage operation likely targeting cryptocurrency users under the guise of wallet services or seed phrase recovery tools. This domain exhibits several red flags consistent with credential harvesting campaigns. It was registered on February 20, 2026, indicating a very recent deployment, which is common in fast-moving phishing operations. VirusTotal currently shows 0 detections out of 95 engines, signaling that signature-based defenses have not yet caught up to this threat. The domain resolves to IP 187.77.176.43, an address with no prior association in threat intelligence databases, further complicating detection. The use of a Let’s Encrypt SSL certificate adds a veneer of legitimacy, making it more likely for victims to enter sensitive data. The registrar, NameSilo, LLC, has been frequently observed in abuse reports tied to spam, phishing, and malware distribution, though registration alone is not inherently malicious. There are no current entries on public blocklists such as Google Safe Browsing, PhishTank, or OpenPhish, suggesting a gap in proactive threat blocking. To mitigate exposure to this threat, users should immediately block access to bitfrost.live at the network level and avoid visiting the domain. If credentials or private keys have been entered, users must revoke all associated wallet access, transfer remaining funds to a new wallet, and enable two-factor authentication on all related accounts. Organizations should add the domain and IP (187.77.176.43) to internal blocklists and monitor for outbound connections to these indicators. Security teams should also inspect DNS logs for queries to bitfrost.live and scan endpoints for signs of credential theft or wallet-related malware. Given the domain’s low detection status, updating threat intelligence feeds with this IOC and reporting it to CERTs and domain registrars can help accelerate remediation. Proactive threat hunting for similar domains with recent creation dates and low trust scores is recommended to prevent further spread of this campaign.
भेजे गए प्रमाण का स्नैपशॉट
- भेजा गया
- लेज़र रिकॉर्ड
- 1
- केस आईडी
PD-20260415-0BB5CA- कैप्चर किए गए पेज का शीर्षक
- Bifrost Wallet - Self-custody, multi-chain crypto wallet for DeFi, NFTs and Web3
- PDF दस्तावेज़
- PDF प्रमाण
प्रमाण का पूरा पाठ
Policy Violations: Prohibits “domains and websites engaging in, promoting or facilitating phishing attacks”, spam and malware; abuse reports trigger investigation and suspension
Applicable Laws: CFAA 18 U.S.C. §1030, Wire Fraud 18 U.S.C. §1343, CAN-SPAM Act 15 U.S.C. §7701–7713
Data Coverage
नेटवर्क सुरक्षा इंटेलिजेंस
धमकी प्रतिक्रिया पाइपलाइन
ब्लॉकलिस्ट कवरेज
10 निगरानी वाले बाहरी स्रोत · संग्रहीत स्नैपशॉट 11/08/2026
सहेजा गया कैप्चर
डोमेन इंटेलिजेंस
तकनीकी विवरणDNS, TLS नाम और समय-मुद्राएँ
ICANN OVERSIGHT
प्रत्यायन और आरएए संदर्भ
प्रत्यायन और आरएए संदर्भ
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
वायरसटोटल विश्लेषण
साइट प्रदर्शन विश्लेषण
Google PageSpeed Insights — mobile performance audit of bitfrost.live · checked Apr 15, 2026
क्या आप इस साइट से प्रभावित हुए?
यदि आपने खाता क्रेडेंशियल, व्यक्तिगत या भुगतान जानकारी दर्ज की है, या इस डोमेन से कोई फ़ाइल डाउनलोड की है, तो तुरंत कार्रवाई करें। घटना की रिपोर्ट करने और अपनी सुरक्षा करने में आपकी सहायता के लिए नीचे संसाधन दिए गए हैं।
अपने स्थानीय अधिकारियों को रिपोर्ट करें
आधिकारिक साइबर अपराध संपर्क, या एक शिकायत ड्राफ्ट बनाएं → प्राप्त करने के लिए अपना देश चुनें।
किसी भी डोमेन की जाँच करें
संग्रहीत ब्लॉकलिस्ट, WHOIS, DNS और सार्वजनिक स्कैन साक्ष्य का उपयोग करके खतरे का विश्लेषण
अभी स्कैन करेंफ़िशिंग की रिपोर्ट करें
संदिग्ध डोमेन हमारे थ्रेट डेटाबेस में जमा करें — समुदाय की सुरक्षा करें
रिपोर्ट करेंसीधा खतरा फीड
हाल की फ़िशिंग रिपोर्टें और उपलब्धता में परिवर्तन देखे गए
निगरानी करेंजानकारी में रहें, सुरक्षित रहें
लाइव खतरों की निगरानी करें या यदि आपको लगता है कि यह एक गलत सकारात्मक है तो इस लिस्टिंग को चुनौती दें।