suite-en[.]framer[.]ai
“Connect & Find Your Trezor”
suite-en.framer.ai — सामग्री अनुपलब्ध. ब्रांड प्रतिरूपण: Trezor; घोटाले का प्रकार: Crypto Scam. साक्ष्य सारांश: VirusTotal 10/95 (alphaMountain.ai, CyRadar, ESET, Forcepoint ThreatSeeker, Fortinet); URLScan malicious verdict; CF Radar malicious; PhishDestroy score 80/100. रजिस्ट्रार: CSC.
मूल फॉरेंसिक रिकॉर्ड सुरक्षित रखने के लिए नीचे का विस्तृत PhishDestroy AI विश्लेषण अंग्रेज़ी में रखा गया है।
On July 25, 2026, the domain suite-en.framer.ai was observed offline and is currently listed by PhishDestroy as a malicious site that impersonates the cryptocurrency hardware‑wallet brand Trezor. The site’s page title, “Connect & Find Your Trezor,” directly references the target brand, confirming a brand‑impersonation tactic. Registry data shows the domain was registered on 6 January 2018 through CSC Corporate Domains, Inc. The hosting resolves to the IP address 64.29.17.195, which belongs to Amazon.com, Inc. (AS16509) and is geolocated in the United States. DNS resolution uses four Amazon Route 53 nameservers: ns-114.awsdns-14.com, ns-1198.awsdns-21.org, ns-1902.awsdns-45.co.uk, and ns-635.awsdns. The TLS certificate is issued by Let’s Encrypt (E8), and the site advertised HSTS and HTTP/3 support.
A technology fingerprint identified Framer Sites and React, consistent with a modern front‑end stack. When queried, the HTTP response returned a 404 status code, indicating the content is not being served at the time of check. VirusTotal analysis returned 10 detections out of 95 scanners, and the domain appears on a single external blocklist, reinforcing its malicious classification. The threat is categorized as a “Crypto Scam,” suggesting the actors may attempt to harvest credentials or lure victims into fraudulent crypto‑related transactions. The presence of a valid TLS certificate does not mitigate risk, as encrypted channels are routinely used by malicious actors to gain user trust.
Uncertainties remain regarding the current payload or credential‑capture mechanisms because the site is offline and no page content was captured. Defenders should continue to block the domain at network perimeters, update DNS filtering policies, and ensure that endpoint protection solutions incorporate the latest indicator set, including the domain name, its IP address, and the associated nameservers.
नेटवर्क सुरक्षा इंटेलिजेंस
धमकी प्रतिक्रिया पाइपलाइन
सार्वजनिक ब्लॉकलिस्ट स्थिति
तकनीकें · 4 identified
JavaScript library for building user interfaces with component-based architecture.
HTTP Strict Transport Security — forces browsers to use HTTPS connections only.
Third major version of HTTP protocol, built on QUIC for faster, more reliable connections.
वायरसटोटल विश्लेषण
संग्रहीत साक्ष्य
साक्ष्य और बाहरी रिपोर्टें
क्या आप इस साइट से प्रभावित हुए?
यदि आपने खाता क्रेडेंशियल, व्यक्तिगत या भुगतान जानकारी दर्ज की है, या इस डोमेन से कोई फ़ाइल डाउनलोड की है, तो तुरंत कार्रवाई करें। घटना की रिपोर्ट करने और अपनी सुरक्षा करने में आपकी सहायता के लिए नीचे संसाधन दिए गए हैं।
अपने स्थानीय अधिकारियों को रिपोर्ट करें
आधिकारिक साइबर अपराध संपर्क, या एक शिकायत ड्राफ्ट बनाएं → प्राप्त करने के लिए अपना देश चुनें।
किसी भी डोमेन की जाँच करें
संग्रहीत ब्लॉकलिस्ट, WHOIS, DNS और सार्वजनिक स्कैन साक्ष्य का उपयोग करके खतरे का विश्लेषण
अभी स्कैन करेंफ़िशिंग की रिपोर्ट करें
संदिग्ध डोमेन हमारे थ्रेट डेटाबेस में जमा करें — समुदाय की सुरक्षा करें
रिपोर्ट करेंसीधा खतरा फीड
हाल की फ़िशिंग रिपोर्टें और उपलब्धता में परिवर्तन देखे गए
निगरानी करेंजानकारी में रहें, सुरक्षित रहें
लाइव खतरों की निगरानी करें या यदि आपको लगता है कि यह एक गलत सकारात्मक है तो इस लिस्टिंग को चुनौती दें।