support-trezorbridge[.]framer[.]ai
“Trézor Bridge® | Secure Hardware Wallet Connection”
support-trezorbridge.framer.ai — Conteúdo indisponível. Representação da marca: Trezor; Tipo de golpe: Brand Impersonation. Resumo das evidências: VirusTotal 2/91 (ChainPatrol, Kaspersky); URLScan malicious verdict; 2 external blocklist matches (MetaMask, SEAL); PhishDestroy score 66/100. Registrador: CSC.
A análise detalhada do PhishDestroy AI permanece em inglês para preservar o registro forense original.
This domain, support-trezorbridge.framer.ai, poses a high-risk threat by impersonating a legitimate hardware wallet provider to deceive users into disclosing sensitive cryptocurrency credentials or installing malicious software. The site mimics the Trezor Bridge interface, a tool used for secure communication between hardware wallets and user devices, with the page title explicitly displaying 'Trézor Bridge® | Secure Hardware Wallet Connection.' Such impersonation is designed to exploit trust in established brands, potentially leading to unauthorized access to cryptocurrency wallets or the execution of crypto-draining malware. Analysis of the domain reveals multiple technical indicators of malicious intent. The domain resolves to the IP address 31.43.161.6 and was registered on January 06, 2018, through CSC Corporate Domains, Inc. Despite its long-standing registration, it remains active and has been flagged by 2 out of 95 security vendors on VirusTotal as malicious. The SSL certificate is issued by Let's Encrypt, which, while providing encryption, does not validate the legitimacy of the site's content. No additional blocklist entries were identified beyond the VirusTotal detections, though the low detection rate may indicate evasion techniques or recent activation of the phishing infrastructure. Users who have visited support-trezorbridge.framer.ai or interacted with its content should take immediate remedial actions to mitigate potential risks. Disconnect any devices that may have established a connection with the domain and revoke any permissions granted to associated applications. Conduct a thorough scan of the affected system using updated security tools to detect and remove any installed malware. Additionally, monitor cryptocurrency wallets linked to the device for unauthorized transactions and consider transferring assets to a new wallet if compromise is suspected. Users are advised to verify the authenticity of any hardware wallet software by accessing it exclusively through the official vendor's domain and to enable multi-factor authentication where available.
Pipeline de resposta a ameaças
Status da lista de bloqueios pública
Análise do VirusTotal
Evidências arquivadas
Evidências e relatórios externos
PD-20260626-86460E Recipient: abuse@framer.com Você foi afetado por este site?
Se você inseriu credenciais de conta, informações pessoais ou de pagamento, ou baixou um arquivo deste domínio, tome medidas imediatas. Abaixo estão os recursos para ajudá-lo a relatar o incidente e se proteger.
Notifique as autoridades locais
Selecione seu país para obter contactos oficiais do cibercrime ou crie um rascunho de reclamação →.
Verificar qualquer domínio
Análise de ameaças usando lista de bloqueio armazenada, WHOIS, DNS e evidências de verificação pública
Digitalize agoraDenunciar phishing
Envie domínios suspeitos para nosso banco de dados de ameaças — proteja a comunidade
DenunciarFeed de ameaças em tempo real
Relatórios recentes de phishing e alterações de disponibilidade observadas
MonitorarMantenha-se informado, mantenha-se seguro
Monitore ameaças em tempo real ou conteste esta listagem caso acredite que se trate de um falso positivo