bc1recovery[.]com
“C1 Recovery – Swiss Blockchain Forensics & Digital Asset Recovery”
bc1recovery.com — Não verificado. Representação da marca: Across; Tipo de golpe: Wallet/seed Phishing. Resumo das evidências: VirusTotal 3/91 (alphaMountain.ai, CRDF, Gridinsoft); PhishDestroy score 69/100. Registrador: NameCheap.
A análise detalhada do PhishDestroy AI permanece em inglês para preservar o registro forense original.
The domain bc1recovery.com is currently active and has been identified as a wallet/seed phishing site that impersonates the brand Across. Registration data show the domain was created on 13 October 2025 through NameCheap, Inc., and it resolves to the IPv4 address 198.177.120.44, which is hosted in the Netherlands under ASN 22612 owned by Namecheap. The web server responds with HTTP status 200 and advertises LiteSpeed as the underlying technology. An SSL certificate issued by Sectigo Limited, signed by the Sectigo RSA Domain Validation Secure Server CA, is present, indicating that transport encryption is in place but does not mitigate the malicious intent.
Reputation services assign extremely low trust scores: Gridinsoft reports a score of 4 out of 100, while Scamadviser rates the domain at 1 out of 100, reflecting high risk. VirusTotal analysis shows that four of ninety‑five scanning engines flagged the domain as malicious, and it appears on a single security blocklist. AlienVault OTX lists the domain in one threat‑intelligence pulse, confirming its recognition by the broader security community. The domain’s MX configuration includes a primary mail exchanger mx1-hosting.jellyfish.systems with priority 5 and a secondary entry at priority 10 (host information truncated).
PhishDestroy has already blocked the domain, but the site remains reachable. The page title returned by the server reads “C1 Recovery – Swiss Blockchain Forensics & Digital Asset Recovery”, which aligns with the declared scam type. Defenders should add the IP address 198.177.120.44 and the domain bc1recovery.com to blocklists, monitor DNS queries for the associated nameservers dns1.namecheaphosting.com and dns2.namecheaphosting.com, and enforce URL filtering based on the observed page title and SSL certificate fingerprint. Continuous re‑evaluation is advised, as the infrastructure could be repurposed for additional phishing campaigns.
Sinais de segurança
Pipeline de resposta a ameaças
Status da lista de bloqueios pública
Captura armazenada
Inteligência de Domínios
Detalhes técnicosDNS, SANs do SSL, carimbos de data e hora
ICANN OVERSIGHT
Credenciamento e contexto RAA
Credenciamento e contexto RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Tecnologias · 1 identified
High-performance web server compatible with Apache configurations.
Análise do VirusTotal
Evidências arquivadas
Análise de desempenho do site
Google PageSpeed Insights — mobile performance audit of bc1recovery.com · checked Mar 26, 2026
Evidências e relatórios externos
“Incident Summary On December 12, 2025, around 18:12 CET, I was contacted by the foreign number +46719100556. The caller stated they were contacting me from the United Kingdom and claimed that a specific cryptocurrency wallet contained 2 Bitcoin (BTC) allocated to me, but that these funds were currently blocked. In order to unlock the 2 BTC, I was immediately requested to make a cryptocurrency transaction (a payment) to a specific external wallet address. The caller claime”
Você foi afetado por este site?
Se você inseriu credenciais de conta, informações pessoais ou de pagamento, ou baixou um arquivo deste domínio, tome medidas imediatas. Abaixo estão os recursos para ajudá-lo a relatar o incidente e se proteger.
Notifique as autoridades locais
Selecione seu país para obter contactos oficiais do cibercrime ou crie um rascunho de reclamação →.
Verificar qualquer domínio
Análise de ameaças usando lista de bloqueio armazenada, WHOIS, DNS e evidências de verificação pública
Digitalize agoraDenunciar phishing
Envie domínios suspeitos para nosso banco de dados de ameaças — proteja a comunidade
DenunciarFeed de ameaças em tempo real
Relatórios recentes de phishing e alterações de disponibilidade observadas
MonitorarMantenha-se informado, mantenha-se seguro
Monitore ameaças em tempo real ou conteste esta listagem caso acredite que se trate de um falso positivo