phantomwallett--secures[.]framer[.]ai
“Site Not Found | Framer”
phantomwallett--secures.framer.ai — Conteúdo indisponível. Representação da marca: Phantom; Tipo de golpe: Crypto Scam. Resumo das evidências: VirusTotal 1/95 (ChainPatrol); PhishDestroy score 55/100. Registrador: CSC.
A análise detalhada do PhishDestroy AI permanece em inglês para preservar o registro forense original.
Analysis of the domain phantomwallett--secures.framer.ai shows a clear alignment with a brand‑impersonation campaign targeting Phantom users. The site is hosted on Amazon Web Services (AS16509) in the United States and resolves to IP address 35.71.142.77. The domain was registered on 6 January 2018 through CSC Corporate Domains, Inc., and it employs a Let’s Encrypt certificate (issuer E8) that provides TLS encryption and HSTS enforcement. Technical fingerprinting reveals the use of Framer Sites, React, and HTTP/3, confirming that the infrastructure is built on a modern web‑app stack rather than a static phishing landing page.
The domain is served by four AWS Route 53 nameservers (ns-114.awsdns-14.com, ns-1198.awsdns-21.org, ns-1902.awsdns-45.co.uk, ns-635.awsdns). HTTP requests return a 404 status code and the page title is “Site Not Found | Framer,” indicating that the content has been removed or the site is deliberately taken offline. Despite the removal, the domain remains listed on at least one security blocklist and is flagged by PhishDestroy, providing external confirmation of malicious intent. VirusTotal reports a single detection out of ninety‑five scanners, reinforcing the suspicion without establishing a definitive verdict.
The known scam type is a crypto‑related impersonation, but the exact payload or credential‑harvesting mechanism has not been captured. Defenders should continue to block the hostname and associated IP address at network perimeter devices, monitor DNS queries for the listed nameservers, and add the domain to internal threat‑intel feeds. Because the site is currently offline, ongoing surveillance is advised to detect any re‑activation or migration to new infrastructure.
Pipeline de resposta a ameaças
Status da lista de bloqueios pública
Tecnologias · 4 identified
JavaScript library for building user interfaces with component-based architecture.
HTTP Strict Transport Security — forces browsers to use HTTPS connections only.
Third major version of HTTP protocol, built on QUIC for faster, more reliable connections.
Análise do VirusTotal
Evidências arquivadas
Evidências e relatórios externos
Você foi afetado por este site?
Se você inseriu credenciais de conta, informações pessoais ou de pagamento, ou baixou um arquivo deste domínio, tome medidas imediatas. Abaixo estão os recursos para ajudá-lo a relatar o incidente e se proteger.
Notifique as autoridades locais
Selecione seu país para obter contactos oficiais do cibercrime ou crie um rascunho de reclamação →.
Verificar qualquer domínio
Análise de ameaças usando lista de bloqueio armazenada, WHOIS, DNS e evidências de verificação pública
Digitalize agoraDenunciar phishing
Envie domínios suspeitos para nosso banco de dados de ameaças — proteja a comunidade
DenunciarFeed de ameaças em tempo real
Relatórios recentes de phishing e alterações de disponibilidade observadas
MonitorarMantenha-se informado, mantenha-se seguro
Monitore ameaças em tempo real ou conteste esta listagem caso acredite que se trate de um falso positivo