MALICIOUS — CRITICAL
Frigober.cc Credential Theft Campaign Targets Unsuspecting Users
frigober[.]
PhishDestroy identifies frigober.cc as an active domain engaged in a generic phishing campaign designed to harvest user credentials and sensitive information.
- VirusTotal
- 6/92
- Blocklists
- 2 · MetaMask, SEAL
- 가용성
- 콘텐츠를 사용할 수 없음 · HTTP 502
Do not enter credentials, seed phrases, payment details, or personal information on this domain.
Jump to section
frigober.cc — 콘텐츠를 사용할 수 없음 (HTTP 502). 브랜드 사칭: Bitget; 사기 유형: Brand Impersonation. 증거 요약: VirusTotal 6/92 (alphaMountain.ai, Emsisoft, Forcepoint ThreatSeeker, LevelBlue, Netcraft); URLQuery 2 alerts; 2 external blocklist matches (MetaMask, SEAL); PhishDestroy score 76/100. 등록기관: Dominet (HK).
원본 포렌식 기록을 보존하기 위해 아래의 상세 PhishDestroy AI 분석은 영어로 유지됩니다.
Evidence Analysis
PhishDestroy identifies frigober.cc as an active domain engaged in a generic phishing campaign designed to harvest user credentials and sensitive information. This domain, registered on April 30, 2026, through Dominet (HK) Limited, poses an elevated threat to users who may encounter it through deceptive emails, fake login portals, or spoofed websites. The threat actor behind this campaign leverages social engineering tactics to trick victims into entering login credentials, payment details, or personal data into fraudulent forms hosted on this domain. Security researchers note that frigober.cc resolves to IP address 103.45.65.15, which has been associated with previous malicious activities, further increasing the risk profile of this domain. This domain was flagged by 5 out of 95 VirusTotal security vendors, indicating a high likelihood of malicious intent. Additionally, the domain’s recent creation date (April 30, 2026) suggests a hastily deployed infrastructure, a common tactic among cybercriminals to evade detection. The use of a Let's Encrypt SSL certificate adds a false sense of legitimacy, as many users associate HTTPS with security, unaware that threat actors can easily obtain such certificates. The combination of a newly registered domain, a low but non-zero detection rate, and a history of malicious IP associations underscores the elevated risk posed by frigober.cc. Users who have visited frigober.cc should immediately cease any interaction with the site and avoid entering any credentials or personal information. If you have entered login details, change your passwords immediately for the affected accounts and enable multi-factor authentication where possible. Scan your device for malware using reputable security software, as this domain may also host or redirect to malicious payloads. Report the domain to your email provider and security teams, and consider blocking it at the network level to prevent further exposure. Staying vigilant and verifying the authenticity of websites before entering sensitive data is critical in mitigating the risks posed by emerging phishing campaigns like the one associated with frigober.cc.
Stored source results
Recorded verdicts and infrastructure observations for this domain.
데이터 적용 범위12 recorded checks
네트워크 보안 인텔리전스
위협 대응 Pipeline
공개 차단 목록 상태
사용 기술 · 3 identified
Vue.js is an open-source model–view–viewmodel JavaScript framework for building user interfaces and single-page applications.
vuejs.org 신뢰도 100%Nginx is a web server that can also be used as a reverse proxy, load balancer, mail proxy and HTTP cache.
nginx.org 신뢰도 100%HTTP Strict Transport Security (HSTS) informs browsers that the site should only be accessed using HTTPS.
www.rfc-editor.org 신뢰도 100%VirusTotal 분석
보관된 증거
증거 및 외부 보고서Independent lookups and source reports
PD-20260511-D6BB9A Recipient: domainabuse@service.aliyun.com Victim safety and official reportingImmediate actions and verified reporting channels
계정 자격 증명, 개인 정보 또는 결제 정보를 입력했거나 이 도메인에서 파일을 다운로드한 경우 즉시 조치를 취하세요. 다음은 사건을 신고하고 자신을 보호하는 데 도움이 되는 리소스입니다.
지역 당국에 신고하십시오
공식 사이버 범죄 연락처 또는 불만사항 초안 작성 →를 받으려면 국가를 선택하세요.