coral-basis-767942[.]framer[.]app
“Yumi Finance”
coral-basis-767942.framer.app — Conteúdo indisponível. Tipo de golpe: Crypto Drainer. Resumo das evidências: VirusTotal 3/94 (ChainPatrol, alphaMountain.ai, Seclookup); URLQuery 1 alert; 2 external blocklist matches (MetaMask, SEAL); PhishDestroy score 71/100. Registrador: Framer.
A análise detalhada do PhishDestroy AI permanece em inglês para preservar o registro forense original.
This domain, coral-basis-767942.framer.app, operates as a crypto drainer designed to impersonate Yumi Finance, a legitimate decentralized finance platform. The site prompts visitors to connect their cryptocurrency wallets under false pretenses, such as claiming airdrops, staking rewards, or exclusive token distributions. Once connected, the malicious smart contract embedded in the site executes unauthorized transactions, draining funds from the victim's wallet without consent. Crypto drainers are particularly insidious because they exploit the irreversible nature of blockchain transactions, leaving victims with no recourse for recovery. The use of a well-known brand like Yumi Finance increases the likelihood of successful deception, especially among users familiar with the legitimate platform's offerings. Analysis indicates this infrastructure was purpose-built for fraudulent activity. The domain is hosted on Framer Sites, a platform that allows rapid deployment of web pages without extensive technical expertise, making it attractive for threat actors. It resolves to the IP address 31.43.161.6 and employs a Let's Encrypt SSL certificate, which provides HTTPS encryption but does not validate the legitimacy of the site's content. Security vendors on VirusTotal have flagged this domain, with 3 out of 95 engines detecting it as malicious. Additionally, the domain appears on three security blocklists and is actively blocked by wallet security tools and phishing detection systems. The page title explicitly mimics Yumi Finance, and the site uses modern web technologies such as React and HTTP/3, which can make it appear more credible to unsuspecting users. If you visited coral-basis-767942.framer.app and connected your wallet, immediate action is required to mitigate potential losses. First, disconnect your wallet from any suspicious sites using your wallet's interface or a trusted dApp browser. Next, revoke any unauthorized smart contract approvals granted to the site by using a token approval revocation tool. Transfer all remaining assets to a new, secure wallet address that has never been exposed to the malicious site. Monitor your transaction history for any unauthorized activity and report the incident to relevant blockchain security teams or community alert platforms. To prevent future incidents, verify the authenticity of any site requesting wallet connections by cross-referencing official sources, such as the project's verified social media accounts or documentation. Always treat unsolicited offers of airdrops or rewards with skepticism, as these are common lures used by crypto drainers.
Inteligência de segurança de rede
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| Quad9 DNS | coral-basis-767942.framer.app |
malicious | Sinkholed |
Pipeline de resposta a ameaças
Status da lista de bloqueios pública
Tecnologias · 4 identified
JavaScript library for building user interfaces with component-based architecture.
HTTP Strict Transport Security — forces browsers to use HTTPS connections only.
Third major version of HTTP protocol, built on QUIC for faster, more reliable connections.
Análise do VirusTotal
Análise de desempenho do site
Google PageSpeed Insights — mobile performance audit of coral-basis-767942.framer.app · checked Jun 26, 2026
Evidências e relatórios externos
PD-20260420-6E2AD9 Recipient: abuse@framer.com Você foi afetado por este site?
Se você inseriu credenciais de conta, informações pessoais ou de pagamento, ou baixou um arquivo deste domínio, tome medidas imediatas. Abaixo estão os recursos para ajudá-lo a relatar o incidente e se proteger.
Notifique as autoridades locais
Selecione seu país para obter contactos oficiais do cibercrime ou crie um rascunho de reclamação →.
Verificar qualquer domínio
Análise de ameaças usando lista de bloqueio armazenada, WHOIS, DNS e evidências de verificação pública
Digitalize agoraDenunciar phishing
Envie domínios suspeitos para nosso banco de dados de ameaças — proteja a comunidade
DenunciarFeed de ameaças em tempo real
Relatórios recentes de phishing e alterações de disponibilidade observadas
MonitorarMantenha-se informado, mantenha-se seguro
Monitore ameaças em tempo real ou conteste esta listagem caso acredite que se trate de um falso positivo