appbifrost.com
“Bifrost: Direct, Instant and Genuine”
appbifrost.com — Контент недоступен. Сводка доказательств: VirusTotal 17/95 (ADMINUSLabs, ChainPatrol, alphaMountain.ai, BitDefender, Chong Lua Dao); Google Safe Browsing flagged; PhishDestroy score 95/100. Регистратор: GoDaddy.
Подробный анализ PhishDestroy AI ниже оставлен на английском, чтобы сохранить исходную криминалистическую запись.
Сводка доказательств
This domain, appbifrost.com, is flagged as a high-risk crypto drainer phishing site designed to illicitly extract cryptocurrency from victims. Analysis indicates the domain impersonates a legitimate service under the guise of "Bifrost: Direct, Instant and Genuine," a common tactic to deceive users into connecting wallets or entering sensitive credentials. The threat type aligns with known crypto drainer schemes, which automatically siphon funds upon interaction, often leaving victims with irreversible losses. Infrastructure analysis reveals multiple critical indicators of compromise. The domain is detected by 17 out of 95 security vendors on VirusTotal, with Google Safe Browsing explicitly flagging it as phishing. It appears on one security blocklist and is currently blocked by PhishDestroy. The domain was registered on January 20, 2025, through GoDaddy.com, LLC, and resolves to the IP address 76.76.21.21, hosted on Amazon.com, Inc. infrastructure (AS16509). Notably, the site lacks an SSL certificate, a red flag for any domain handling sensitive transactions. The page title and branding further suggest an attempt to mimic legitimate cryptocurrency services, increasing the likelihood of successful social engineering. Mitigation steps for this threat type require immediate action from both end-users and network administrators. Users who interacted with appbifrost.com should assume wallet compromise and take the following steps: revoke all connected dApp permissions, transfer remaining funds to a new wallet, and monitor transaction histories for unauthorized activity. Network administrators should block the domain and its resolving IP (76.76.21.21) at the firewall or DNS level to prevent access. Organizations should also update security policies to include this domain in phishing awareness training, emphasizing the risks of crypto drainers. Given the domain’s recent creation and lack of SSL, additional scrutiny should be applied to similarly structured domains registered through the same registrar or hosted on shared infrastructure.
Хронология обнаружения
-
Cloudflare Radar
Сканирование Cloudflare Radar сохранено · Открыть сканирование
-
Статус домена
Доступен → Недоступен
-
VirusTotal
17 → 16 (-1) (Removed: SOCRadar)
Процесс реагирования на угрозы
Статус в публичных блок-листах
Проверка по блок-листам
11 внешних источников под наблюдением · снимок от 10.09.2026
11 внешних источников под наблюдением Совпадений нет
Сохранённый снимок
Аналитика доменов
Технические деталиDNS, SAN в протоколе SSL, временные метки
ICANN OVERSIGHT
Аккредитация и контекст RAA
Аккредитация и контекст RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Технологии · 2 identified
High-performance HTTP server and reverse proxy, known for stability and low resource usage.
Web platform based on Nginx with LuaJIT for scalable web apps.
Анализ VirusTotal
Архивные доказательства
Анализ производительности сайта
Google PageSpeed Insights — mobile performance audit of appbifrost.com · checked Mar 2, 2026
Технологии
Выявлено 2 технологии с высокой уверенностью
Доказательства и внешние отчеты
Повлиял ли на вас этот сайт?
Если вы ввели учетные данные, личную или платежную информацию или загрузили файл с этого домена, примите немедленные меры. Ниже приведены ресурсы, которые помогут вам сообщить об инциденте и защитить себя.
Сообщите об этом в местные органы власти
Выберите свою страну, чтобы получить официальные контакты по киберпреступности или создать проект жалобы →.
Проверить любой домен
Анализ угроз с использованием сохраненного черного списка, WHOIS, DNS и общедоступных доказательств сканирования.
Сканировать сейчасСообщить о фишинге
Добавляйте подозрительные домены в нашу базу данных угроз — защищайте сообщество
СообщитьПоток оперативных данных об угрозах
Недавние сообщения о фишинге и наблюдаемые изменения доступности
ОтслеживатьБудьте в курсе событий, берегите себя
Отслеживайте актуальные угрозы или оспорьте эту запись, если считаете, что это ложное срабатывание