bitfrost[.]live
“Bifrost Wallet - Self-custody, multi-chain crypto wallet for DeFi, NFTs and Web3”
Resumo das evidências
bitfrost.live has been confirmed as an active generic phishing site. This domain poses a high risk by masquerading as a cryptocurrency wallet to harvest user credentials and private keys. The campaign is currently undetected by security vendors, with 0 detections on VirusTotal as of the latest scan, and has not yet been added to public blocklists. Given the domain’s recent creation on February 20, 2026, and the use of a Let’s Encrypt SSL certificate, attackers are leveraging trusted infrastructure to lend credibility to their fraudulent site. The infrastructure is hosted at IP 187.77.176.43, which has no established reputation, and is registered through NameSilo, LLC, a registrar commonly abused for short-lived malicious domains. The combination of low detection rates, new registration, and plausible infrastructure suggests this is an early-stage operation likely targeting cryptocurrency users under the guise of wallet services or seed phrase recovery tools. This domain exhibits several red flags consistent with credential harvesting campaigns. It was registered on February 20, 2026, indicating a very recent deployment, which is common in fast-moving phishing operations. VirusTotal currently shows 0 detections out of 95 engines, signaling that signature-based defenses have not yet caught up to this threat. The domain resolves to IP 187.77.176.43, an address with no prior association in threat intelligence databases, further complicating detection. The use of a Let’s Encrypt SSL certificate adds a veneer of legitimacy, making it more likely for victims to enter sensitive data. The registrar, NameSilo, LLC, has been frequently observed in abuse reports tied to spam, phishing, and malware distribution, though registration alone is not inherently malicious. There are no current entries on public blocklists such as Google Safe Browsing, PhishTank, or OpenPhish, suggesting a gap in proactive threat blocking. To mitigate exposure to this threat, users should immediately block access to bitfrost.live at the network level and avoid visiting the domain. If credentials or private keys have been entered, users must revoke all associated wallet access, transfer remaining funds to a new wallet, and enable two-factor authentication on all related accounts. Organizations should add the domain and IP (187.77.176.43) to internal blocklists and monitor for outbound connections to these indicators. Security teams should also inspect DNS logs for queries to bitfrost.live and scan endpoints for signs of credential theft or wallet-related malware. Given the domain’s low detection status, updating threat intelligence feeds with this IOC and reporting it to CERTs and domain registrars can help accelerate remediation. Proactive threat hunting for similar domains with recent creation dates and low trust scores is recommended to prevent further spread of this campaign.
Instantâneo das evidências enviadas
- Enviado
- Registros do livro-razão
- 1
- ID do caso
PD-20260415-0BB5CA- Título da página capturada
- Bifrost Wallet - Self-custody, multi-chain crypto wallet for DeFi, NFTs and Web3
- Artefato PDF
- Evidência em PDF
Base jurídica
Texto completo da evidência
Policy Violations: Prohibits “domains and websites engaging in, promoting or facilitating phishing attacks”, spam and malware; abuse reports trigger investigation and suspension
Applicable Laws: CFAA 18 U.S.C. §1030, Wire Fraud 18 U.S.C. §1343, CAN-SPAM Act 15 U.S.C. §7701–7713
Data Coverage
Inteligência de segurança de rede
Pipeline de resposta a ameaças
Cobertura de listas de bloqueio
10 fontes externas monitoradas · instantâneo de 12/08/2026
10 fontes externas monitoradas Sem correspondência
Captura armazenada
Inteligência de Domínios
Detalhes técnicosDNS, nomes TLS e datas
ICANN OVERSIGHT
Credenciamento e contexto RAA
Credenciamento e contexto RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Análise do VirusTotal
Análise de desempenho do site
Google PageSpeed Insights — mobile performance audit of bitfrost.live · checked Apr 15, 2026
Você foi afetado por este site?
Se você inseriu credenciais de conta, informações pessoais ou de pagamento, ou baixou um arquivo deste domínio, tome medidas imediatas. Abaixo estão os recursos para ajudá-lo a relatar o incidente e se proteger.
Notifique as autoridades locais
Selecione seu país para obter contactos oficiais do cibercrime ou crie um rascunho de reclamação →.
Verificar qualquer domínio
Análise de ameaças usando lista de bloqueio armazenada, WHOIS, DNS e evidências de verificação pública
Digitalize agoraDenunciar phishing
Envie domínios suspeitos para nosso banco de dados de ameaças — proteja a comunidade
DenunciarFeed de ameaças em tempo real
Relatórios recentes de phishing e alterações de disponibilidade observadas
MonitorarMantenha-se informado, mantenha-se seguro
Monitore ameaças em tempo real ou conteste esta listagem caso acredite que se trate de um falso positivo