setamaskk[.]framer[.]ai
“Site Not Found | Framer”
ملخص الأدلة
Analysis of the domain setamaskk.framer.ai indicates it was involved in a wallet-seed phishing campaign targeting MetaMask users. The domain was registered on April 4, 2023, through CSC Corporate Domains, Inc., and resolved to the IP address 52.223.52.2, hosted on Amazon Web Services (AS16509) in the United States. Nameservers associated with the domain include ns-114.awsdns-14.com, ns-1198.awsdns-21.org, ns-1902.awsdns-45.co.uk, and ns-635.awsdns, further linking it to AWS infrastructure. The SSL certificate was issued by Let's Encrypt, a common choice for both legitimate and malicious domains.
At the time of assessment, the domain returned an HTTP 404 status with the page title 'Site Not Found | Framer,' suggesting it was either taken offline or reconfigured. Despite this, six out of ninety-five security vendors on VirusTotal flagged the domain as malicious, and it appeared on at least one security blocklist, specifically PhishDestroy. The combination of brand impersonation (MetaMask), the use of a hosting provider frequently leveraged for phishing, and detection by multiple security vendors supports the classification of this domain as part of a seed-phishing operation. Defenders should treat this domain as compromised infrastructure.
While it is currently offline, historical resolution to 52.223.52.2 and its registration details may still be useful for retrospective threat hunting. Organizations are advised to block the domain at the DNS level and monitor for any re-emergence or related domains using similar naming conventions or infrastructure. The exact content of the phishing page is not analyzed in this report, but the available evidence aligns with known patterns of cryptocurrency wallet seed-phishing campaigns.
Data Coverage
مسار الاستجابة للتهديدات Pipeline
تغطية قوائم الحظر
١٠ مصادر خارجية مراقبة · لقطة محفوظة 11/08/2026
المخطط الزمني للاكتشاف
معلومات النطاق
التفاصيل التقنيةDNS وأسماء TLS والطوابع الزمنية
تحليل VirusTotal
هل تأثرت بهذا الموقع؟
إذا أدخلت بيانات اعتماد الحساب أو المعلومات الشخصية أو معلومات الدفع أو قمت بتنزيل ملف من هذا النطاق، فاتخذ إجراءً فوريًا. فيما يلي موارد لمساعدتك في الإبلاغ عن الحادث وحماية نفسك.
أبلغ السلطات المحلية
حدد بلدك للحصول على الاتصالات الرسمية المتعلقة بالجرائم الإلكترونية أو إنشاء مسودة شكوى →.
تحقق من أي نطاق
تحليل التهديدات باستخدام قائمة الحظر المخزنة، وWHOIS، وDNS، وأدلة الفحص العامة
امسح الآنالإبلاغ عن محاولة تصيد احتيالي
أرسل النطاقات المشبوهة إلى قاعدة بيانات التهديدات الخاصة بنا — ساهم في حماية المجتمع
إبلاغتحديثات فورية حول التهديدات
تقارير التصيد الاحتيالي الأخيرة وتغييرات التوفر الملحوظة
مراقبةابقَ على اطلاع، وابقَ آمنًا
راقب التهديدات في الوقت الفعلي أو اعترض على هذا الإدراج إذا كنت تعتقد أنه إنذار كاذب