phantam-wallet-ask[.]framer[.]website
“Phantom Wallet – Secure Solana Crypto Wallet”
phantam-wallet-ask.framer.website — Contenido no disponible (HTTP 404). Suplantación de marca: Phantom; Tipo de estafa: Crypto Scam. Resumen de las pruebas: VirusTotal 4/95 (ChainPatrol, alphaMountain.ai, CyRadar, Google Safebrowsing); URLQuery 100 det.; Spamhaus DBL_PHISH; PhishDestroy score 95/100. Registrador: CSC.
El análisis detallado de PhishDestroy AI se mantiene en inglés para conservar el registro forense original.
The domain phantam-wallet-ask.framer.website was registered on November 19, 2021 through CSC Corporate Domains, Inc. It resolves to the Amazon Web Services address 52.223.52.2, which belongs to ASN 16509 (Amazon.com, Inc.) and is geolocated in the United States. The site serves an SSL certificate issued by Let’s Encrypt (E7) and enforces HSTS, indicating a legitimate TLS deployment despite the malicious purpose. Page metadata reports the title "Phantom Wallet – Secure Solana Crypto Wallet," directly referencing the Phantom brand and suggesting a crypto‑wallet impersonation scheme. The underlying stack includes Framer Sites, React, and HTTP/3, typical of modern static‑site generators and not indicative of a compromised server.
VirusTotal analysis shows four of ninety‑five security vendors flag the domain, and it appears on a single external blocklist. PhishDestroy has already taken the domain offline and recorded it as a crypto scam, confirming the brand‑impersonation intent. HTTP probing returned a 404 status, and the site is currently inaccessible, limiting further content inspection. Defenders should treat the domain as a confirmed impersonation of the Phantom wallet and block the hostname and its associated IP at perimeter defenses.
Given the use of shared AWS infrastructure, monitoring for additional subdomains that resolve to the same address or similar naming patterns is advised. Updating threat intelligence feeds with the domain, its nameservers (ns-1243.awsdns-27.org, ns-1818.awsdns-35.co.uk, ns-336.awsdns-42.com, ns-792.awsdns), and the observed TLS fingerprint will help prevent future abuse. Continuous DNS surveillance for new registrations that mimic "Phantom" or employ the framer.website suffix is recommended to catch emerging impersonation campaigns early.
Proceso de respuesta ante amenazas Pipeline
Estado de la lista de bloqueados pública
Tecnologías · 4 identified
JavaScript library for building user interfaces with component-based architecture.
HTTP Strict Transport Security — forces browsers to use HTTPS connections only.
Third major version of HTTP protocol, built on QUIC for faster, more reliable connections.
Análisis de VirusTotal
Evidencias archivadas
Datos y informes externos
¿Te ha afectado esta página web?
Si ingresó credenciales de cuenta, información personal o de pago, o descargó un archivo de este dominio, tome medidas inmediatas. A continuación encontrará recursos que le ayudarán a informar el incidente y protegerse.
Informa a las autoridades locales
Seleccione su país para obtener contactos oficiales de cibercrimen o crear un borrador de queja →.
Comprobar cualquier dominio
Análisis de amenazas utilizando listas de bloqueo almacenadas, WHOIS, DNS y evidencia de escaneo público
Escanear ahoraDenunciar un intento de phishing
Envía los dominios sospechosos a nuestra base de datos de amenazas: protege a la comunidad
DenunciarFlujo de amenazas en tiempo real
Informes de phishing recientes y cambios de disponibilidad observados
MonitorizarMantente informado, mantente a salvo
Supervisa las amenazas en tiempo real o impugna esta entrada si crees que se trata de un falso positivo.