help-kraken-ia[.]framer[.]photos
“Sign In | Kraken® - Login In to Your Account*”
help-kraken-ia.framer.photos — 확인되지 않음. 브랜드 사칭: Kraken; 사기 유형: Crypto Scam. 증거 요약: VirusTotal 12/91 (ChainPatrol, alphaMountain.ai, BitDefender, Chong Lua Dao, CyRadar); Google Safe Browsing flagged; PhishDestroy score 86/100. 등록기관: CSC.
원본 포렌식 기록을 보존하기 위해 아래의 상세 PhishDestroy AI 분석은 영어로 유지됩니다.
On July 24, 2026, the domain help-kraken-ia.framer.photos was observed in an offline state but retains artifacts that indicate a high‑risk brand‑impersonation campaign targeting users of the cryptocurrency exchange Kraken. The site was registered on 19 November 2021 through CSC Corporate Domains, Inc., and is hosted on Amazon’s infrastructure (ASN 16509) in the United States, resolving to 52.223.52.2. DNS resolution lists four AWS name servers (ns-1175.awsdns-18.org, ns-1631.awsdns-11.co.uk, ns-816.awsdns-38.net, ns-195.awsdns). The web server presented a TLS certificate issued by Let’s Encrypt (E7) and advertised HSTS and HTTP/3 support, while the underlying stack included Framer Sites and React. An HTTP request returned a 404 status code and the page title captured was “Sign In | Kraken® - Login In to Your Account*”, matching the brand target.
The page title and the declared impersonation of Kraken confirm the campaign’s intent to harvest credentials for a crypto‑related scam. Threat intelligence aggregators flagged the domain: Google Safe Browsing classified it as social‑engineering, VirusTotal recorded detections by 11 of 95 scanned vendors, and a single security blocklist listed the host, which is also blocked by the PhishDestroy feed. The combination of brand impersonation, the “Crypto Scam” label, and the presence on multiple threat‑intel sources elevates the risk to high. Uncertainty remains regarding the current operational status of the infrastructure, as the site is presently offline and no live content is reachable.
However, the persistence of the domain, its resolver configuration, and the historical detection record suggest that the infrastructure could be re‑activated or reused in future campaigns. Defenders should add the domain and its associated IP address (52.223.52.2) to block lists, monitor DNS queries for the four AWS name servers, and enforce outbound filtering for HTTP/HTTPS traffic to the identified page title pattern.
위협 대응 Pipeline
공개 차단 목록 상태
사용 기술 · 4 identified
Framer is a no-code web design platform for designing and publishing responsive websites.
www.framer.com 신뢰도 100%React is an open-source JavaScript library for building user interfaces or UI components.
reactjs.org 신뢰도 100%HTTP Strict Transport Security (HSTS) informs browsers that the site should only be accessed using HTTPS.
www.rfc-editor.org 신뢰도 100%HTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org 신뢰도 100%VirusTotal 분석
보관된 증거
증거 및 외부 보고서
이 사이트로 인해 영향을 받으셨나요?
계정 자격 증명, 개인 정보 또는 결제 정보를 입력했거나 이 도메인에서 파일을 다운로드한 경우 즉시 조치를 취하세요. 다음은 사건을 신고하고 자신을 보호하는 데 도움이 되는 리소스입니다.
지역 당국에 신고하십시오
공식 사이버 범죄 연락처 또는 불만사항 초안 작성 →를 받으려면 국가를 선택하세요.