The domain activity.octofrost.com is currently listed as an active generic phishing site. Registration data shows the domain was created on 04 December 2006 and is registered through Name SRS AB. DNS resolution points to the IPv4 address 195.216.58.38, and the authoritative name servers are ns1.dnshost.net and ns2.dnshost.net. VirusTotal has recorded five detections out of ninety‑one scanning engines, indicating that a minority of security products have identified malicious content associated with the host.
The domain appears on two public blocklists and is explicitly blocked by PhishDestroy and OpenPhish, reinforcing the assessment of malicious intent. No public SSL/TLS certificate information is available, and the page title has not been disclosed, leaving the appearance and transport security of the site uncertain. The lack of additional telemetry such as HTTP status codes, Safe Browsing verdicts, or OTX indicators means that the full scope of the phishing campaign cannot be quantified at this time.
Defenders should continue to block the domain at perimeter and DNS layers, monitor for connections to 195.216.58.38, and consider adding the domain to internal blocklists. Ongoing observation of the hosting provider and name server activity is advised, as any changes could signal a shift in the campaign’s infrastructure. Given the high risk rating, organizations handling credential or personal data should treat any unsolicited communications referencing activity.octofrost.com as hostile and advise users to avoid interaction.