wallet-phantom[.]framer[.]ai
“Phantom – Get this Extension for Firefox (en-US) - Mozilla”
ملاحظة محفوظة
تباين العناوين المرصود
ملخص الأدلة
The domain wallet-phantom.framer.ai was created on January 06, 2018 through CSC Corporate Domains, Inc. and is served by the AWS DNS set ns-114.awsdns-14.com, ns-1198.awsdns-21.org, ns-1902.awsdns-45.co.uk and ns-635.awsdns. DNS resolution points to the IP address 35.71.142.77, which belongs to AS16509 Amazon.com, Inc., located in the United States. The site presents a TLS certificate issued by Let’s Encrypt (certificate identifier E8) and enforces HSTS, while also supporting HTTP/3. An HTTP request returns a 404 status code and the page title captured during the scan is “Phantom – Get this Extension for Firefox (en-US) - Mozilla”, suggesting a reference to a Mozilla extension page but providing no functional content at the time of observation. Technology fingerprints identify Framer Sites and a React front‑end, consistent with a low‑cost site‑builder deployment.
Threat intelligence classifies the domain as a brand‑impersonation vector targeting the Phantom cryptocurrency wallet, and the scam type is recorded as a crypto scam. The infrastructure is currently marked offline, yet it appears on one security blocklist and has been actively blocked by PhishDestroy. VirusTotal scans show three of ninety‑five security vendors flagging the domain, reinforcing the suspicion of malicious intent despite the lack of active payloads.
Defenders should treat the domain as a high‑confidence indicator of a fraudulent operation aimed at deceiving Phantom users. Immediate mitigation actions include adding the domain and its associated IP address to network deny lists, enforcing URL filtering for any references to Phantom, and configuring browsers to honor Safe Browsing warnings for the site. Continuous monitoring is advised to detect any re‑hosting or content changes, as the offline status may be temporary and the underlying AWS assets could be reused for future campaigns. Until further evidence emerges, the domain should be considered unsafe for any user interaction.
Data Coverage
مسار الاستجابة للتهديدات Pipeline
تغطية قوائم الحظر
١٠ مصادر خارجية مراقبة · لقطة محفوظة 12/08/2026
المخطط الزمني للاكتشاف
-
حالة النطاق
يمكن الوصول إليه ← يتعذر الوصول إليه
-
حالة النطاق
يمكن الوصول إليه ← يتعذر الوصول إليه
-
Cloudflare Radar
تم حفظ فحص Cloudflare Radar · فتح الفحص
التقنيات
حُدّدت ٤ تقنيات عالية الثقة
تحليل VirusTotal
هل تأثرت بهذا الموقع؟
إذا أدخلت بيانات اعتماد الحساب أو المعلومات الشخصية أو معلومات الدفع أو قمت بتنزيل ملف من هذا النطاق، فاتخذ إجراءً فوريًا. فيما يلي موارد لمساعدتك في الإبلاغ عن الحادث وحماية نفسك.
أبلغ السلطات المحلية
حدد بلدك للحصول على الاتصالات الرسمية المتعلقة بالجرائم الإلكترونية أو إنشاء مسودة شكوى →.
تحقق من أي نطاق
تحليل التهديدات باستخدام قائمة الحظر المخزنة، وWHOIS، وDNS، وأدلة الفحص العامة
امسح الآنالإبلاغ عن محاولة تصيد احتيالي
أرسل النطاقات المشبوهة إلى قاعدة بيانات التهديدات الخاصة بنا — ساهم في حماية المجتمع
إبلاغتحديثات فورية حول التهديدات
تقارير التصيد الاحتيالي الأخيرة وتغييرات التوفر الملحوظة
مراقبةابقَ على اطلاع، وابقَ آمنًا
راقب التهديدات في الوقت الفعلي أو اعترض على هذا الإدراج إذا كنت تعتقد أنه إنذار كاذب