phantomwallett--secures[.]framer[.]ai
“Site Not Found | Framer”
phantomwallett--secures.framer.ai — المحتوى غير متوفر. انتحال العلامة التجارية: Phantom; نوع الاحتيال: Crypto Scam. ملخص الأدلة: VirusTotal 1/95 (ChainPatrol); PhishDestroy score 55/100. مسجّل النطاق: CSC.
يبقى تحليل PhishDestroy AI المفصل أدناه باللغة الإنجليزية للحفاظ على السجل الجنائي الرقمي الأصلي.
Analysis of the domain phantomwallett--secures.framer.ai shows a clear alignment with a brand‑impersonation campaign targeting Phantom users. The site is hosted on Amazon Web Services (AS16509) in the United States and resolves to IP address 35.71.142.77. The domain was registered on 6 January 2018 through CSC Corporate Domains, Inc., and it employs a Let’s Encrypt certificate (issuer E8) that provides TLS encryption and HSTS enforcement. Technical fingerprinting reveals the use of Framer Sites, React, and HTTP/3, confirming that the infrastructure is built on a modern web‑app stack rather than a static phishing landing page.
The domain is served by four AWS Route 53 nameservers (ns-114.awsdns-14.com, ns-1198.awsdns-21.org, ns-1902.awsdns-45.co.uk, ns-635.awsdns). HTTP requests return a 404 status code and the page title is “Site Not Found | Framer,” indicating that the content has been removed or the site is deliberately taken offline. Despite the removal, the domain remains listed on at least one security blocklist and is flagged by PhishDestroy, providing external confirmation of malicious intent. VirusTotal reports a single detection out of ninety‑five scanners, reinforcing the suspicion without establishing a definitive verdict.
The known scam type is a crypto‑related impersonation, but the exact payload or credential‑harvesting mechanism has not been captured. Defenders should continue to block the hostname and associated IP address at network perimeter devices, monitor DNS queries for the listed nameservers, and add the domain to internal threat‑intel feeds. Because the site is currently offline, ongoing surveillance is advised to detect any re‑activation or migration to new infrastructure.
مسار الاستجابة للتهديدات Pipeline
حالة قوائم الحظر العامة
التقنيات · 4 identified
JavaScript library for building user interfaces with component-based architecture.
HTTP Strict Transport Security — forces browsers to use HTTPS connections only.
Third major version of HTTP protocol, built on QUIC for faster, more reliable connections.
تحليل VirusTotal
الأدلة المؤرشفة
الأدلة والتقارير الخارجية
هل تأثرت بهذا الموقع؟
إذا أدخلت بيانات اعتماد الحساب أو المعلومات الشخصية أو معلومات الدفع أو قمت بتنزيل ملف من هذا النطاق، فاتخذ إجراءً فوريًا. فيما يلي موارد لمساعدتك في الإبلاغ عن الحادث وحماية نفسك.
أبلغ السلطات المحلية
حدد بلدك للحصول على الاتصالات الرسمية المتعلقة بالجرائم الإلكترونية أو إنشاء مسودة شكوى →.
تحقق من أي نطاق
تحليل التهديدات باستخدام قائمة الحظر المخزنة، وWHOIS، وDNS، وأدلة الفحص العامة
امسح الآنالإبلاغ عن محاولة تصيد احتيالي
أرسل النطاقات المشبوهة إلى قاعدة بيانات التهديدات الخاصة بنا — ساهم في حماية المجتمع
إبلاغتحديثات فورية حول التهديدات
تقارير التصيد الاحتيالي الأخيرة وتغييرات التوفر الملحوظة
مراقبةابقَ على اطلاع، وابقَ آمنًا
راقب التهديدات في الوقت الفعلي أو اعترض على هذا الإدراج إذا كنت تعتقد أنه إنذار كاذب