setamaskk[.]framer[.]ai
“Site Not Found | Framer”
Résumé des preuves
Analysis of the domain setamaskk.framer.ai indicates it was involved in a wallet-seed phishing campaign targeting MetaMask users. The domain was registered on April 4, 2023, through CSC Corporate Domains, Inc., and resolved to the IP address 52.223.52.2, hosted on Amazon Web Services (AS16509) in the United States. Nameservers associated with the domain include ns-114.awsdns-14.com, ns-1198.awsdns-21.org, ns-1902.awsdns-45.co.uk, and ns-635.awsdns, further linking it to AWS infrastructure. The SSL certificate was issued by Let's Encrypt, a common choice for both legitimate and malicious domains.
At the time of assessment, the domain returned an HTTP 404 status with the page title 'Site Not Found | Framer,' suggesting it was either taken offline or reconfigured. Despite this, six out of ninety-five security vendors on VirusTotal flagged the domain as malicious, and it appeared on at least one security blocklist, specifically PhishDestroy. The combination of brand impersonation (MetaMask), the use of a hosting provider frequently leveraged for phishing, and detection by multiple security vendors supports the classification of this domain as part of a seed-phishing operation. Defenders should treat this domain as compromised infrastructure.
While it is currently offline, historical resolution to 52.223.52.2 and its registration details may still be useful for retrospective threat hunting. Organizations are advised to block the domain at the DNS level and monitor for any re-emergence or related domains using similar naming conventions or infrastructure. The exact content of the phishing page is not analyzed in this report, but the available evidence aligns with known patterns of cryptocurrency wallet seed-phishing campaigns.
Data Coverage
Processus de réponse aux menaces Pipeline
Couverture des listes de blocage
10 sources externes surveillées · instantané du 12/08/2026
10 sources externes surveillées Aucune correspondance
Chronologie de détection
-
État du domaine
Accessible → Inaccessible
-
Cloudflare Radar
Analyse Cloudflare Radar enregistrée · Ouvrir l’analyse
-
Cloudflare Radar
Analyse Cloudflare Radar enregistrée · Ouvrir l’analyse
Informations sur les domaines
Détails techniquesDNS, noms TLS et horodatages
Analyse VirusTotal
Ce site vous a-t-il affecté ?
Si vous avez saisi des informations d'identification de compte, des informations personnelles ou de paiement, ou téléchargé un fichier à partir de ce domaine, agissez immédiatement. Vous trouverez ci-dessous des ressources pour vous aider à signaler l'incident et à vous protéger.
Signalez-le à vos autorités locales
Sélectionnez votre pays pour obtenir contacts officiels en matière de cybercriminalité ou créer un projet de plainte →.
Vérifier n'importe quel domaine
Analyse des menaces à l'aide de listes de blocage stockées, de WHOIS, de DNS et de preuves d'analyse publique
Scanner maintenantSignaler une tentative d'hameçonnage
Signalez les domaines suspects à notre base de données des menaces — protégez la communauté
SignalerFlux d'alertes en temps réel
Rapports de phishing récents et changements de disponibilité observés
SurveillerRestez informés, restez en sécurité
Surveillez les menaces en temps réel ou signalez cette alerte si vous pensez qu'il s'agit d'un faux positif