wallet-phantom[.]framer[.]ai
“Phantom – Get this Extension for Firefox (en-US) - Mozilla”
Сохранённое наблюдение
Зафиксированное различие заголовков
Сводка доказательств
The domain wallet-phantom.framer.ai was created on January 06, 2018 through CSC Corporate Domains, Inc. and is served by the AWS DNS set ns-114.awsdns-14.com, ns-1198.awsdns-21.org, ns-1902.awsdns-45.co.uk and ns-635.awsdns. DNS resolution points to the IP address 35.71.142.77, which belongs to AS16509 Amazon.com, Inc., located in the United States. The site presents a TLS certificate issued by Let’s Encrypt (certificate identifier E8) and enforces HSTS, while also supporting HTTP/3. An HTTP request returns a 404 status code and the page title captured during the scan is “Phantom – Get this Extension for Firefox (en-US) - Mozilla”, suggesting a reference to a Mozilla extension page but providing no functional content at the time of observation. Technology fingerprints identify Framer Sites and a React front‑end, consistent with a low‑cost site‑builder deployment.
Threat intelligence classifies the domain as a brand‑impersonation vector targeting the Phantom cryptocurrency wallet, and the scam type is recorded as a crypto scam. The infrastructure is currently marked offline, yet it appears on one security blocklist and has been actively blocked by PhishDestroy. VirusTotal scans show three of ninety‑five security vendors flagging the domain, reinforcing the suspicion of malicious intent despite the lack of active payloads.
Defenders should treat the domain as a high‑confidence indicator of a fraudulent operation aimed at deceiving Phantom users. Immediate mitigation actions include adding the domain and its associated IP address to network deny lists, enforcing URL filtering for any references to Phantom, and configuring browsers to honor Safe Browsing warnings for the site. Continuous monitoring is advised to detect any re‑hosting or content changes, as the offline status may be temporary and the underlying AWS assets could be reused for future campaigns. Until further evidence emerges, the domain should be considered unsafe for any user interaction.
Data Coverage
Процесс реагирования на угрозы
Проверка по блок-листам
10 внешних источников под наблюдением · снимок от 12.08.2026
10 внешних источников под наблюдением Совпадений нет
Хронология обнаружения
-
Статус домена
Доступен → Недоступен
-
Статус домена
Доступен → Недоступен
-
Cloudflare Radar
Сканирование Cloudflare Radar сохранено · Открыть сканирование
Технологии
Выявлено 4 технологии с высокой уверенностью
Анализ VirusTotal
Повлиял ли на вас этот сайт?
Если вы ввели учетные данные, личную или платежную информацию или загрузили файл с этого домена, примите немедленные меры. Ниже приведены ресурсы, которые помогут вам сообщить об инциденте и защитить себя.
Сообщите об этом в местные органы власти
Выберите свою страну, чтобы получить официальные контакты по киберпреступности или создать проект жалобы →.
Проверить любой домен
Анализ угроз с использованием сохраненного черного списка, WHOIS, DNS и общедоступных доказательств сканирования.
Сканировать сейчасСообщить о фишинге
Добавляйте подозрительные домены в нашу базу данных угроз — защищайте сообщество
СообщитьПоток оперативных данных об угрозах
Недавние сообщения о фишинге и наблюдаемые изменения доступности
ОтслеживатьБудьте в курсе событий, берегите себя
Отслеживайте актуальные угрозы или оспорьте эту запись, если считаете, что это ложное срабатывание