startiio[.]framer[.]media
“Ledger.com/Start® | Getting started — Ledger Support”
Kanıt özeti
The domain startiio.framer.media has been identified as a high-risk brand impersonation site targeting Ledger, a cryptocurrency hardware wallet provider. Analysis indicates this domain was designed to deceive users into believing they were accessing legitimate Ledger support resources, specifically mimicking the Ledger.com/Start onboarding page. The domain is currently offline, but prior activity suggests it was operational long enough to pose a significant threat to unsuspecting users. Infrastructure analysis reveals the domain was registered through CSC Corporate Domains, Inc., and resolved to the IP address 31.43.160.6. It was flagged by 18 of 95 security vendors on VirusTotal, indicating widespread detection as malicious. The domain appeared on three security blocklists, including PhishDestroy, PhishingArmy, and OISD. The SSL certificate was issued by Let's Encrypt, a common choice for both legitimate and malicious sites due to its accessibility. Technologies detected on the domain include Framer Sites, React, HSTS, and HTTP/3, which are consistent with modern web development practices but do not inherently indicate legitimacy. The page title, "Ledger.com/Start® | Getting started — Ledger Support," was explicitly crafted to mimic the official Ledger support portal, increasing the likelihood of successful user deception. Current status confirms the domain has been taken offline, reducing immediate risk to users. However, the infrastructure and techniques observed are consistent with persistent threats in the cryptocurrency space, particularly those targeting hardware wallet users. Organizations and individuals are advised to block the domain and its associated IP address (31.43.160.6) at the network level. Users who may have interacted with this domain should immediately revoke any connected wallet permissions, rotate credentials, and monitor for unauthorized transactions. Security teams are encouraged to review logs for connections to the domain or IP address and investigate potential compromise. Proactive monitoring for similar impersonation domains, particularly those using Let's Encrypt certificates and modern web frameworks, is recommended to mitigate future risks.
Gönderilen kanıt anlık görüntüsü
- Gönderildi
- Kayıt defteri kayıtları
- 1
- Vaka kimliği
PD-20260530-16123B- Yakalanan sayfa başlığı
- Ledger.com/Start® | Getting started — Ledger Support
- PDF belgesi
- PDF kanıtı
Hukuki dayanak
Kanıtın tam metni
Acceptable Use Policy (AUP): The domain startiio.framer.media is engaged in phishing activities, which directly contravenes the prohibition against illegal activities, fraud, and deception outlined in your AUP.
Terms of Service (TOS): The use of this domain for fraudulent purposes constitutes a violation of your TOS, which reserves the right to suspend or terminate services for any activities that breach legal standards or your policies.
Applicable Laws (Unknown):
Computer Fraud and Abuse Act (CFAA): This U.S. law prohibits unauthorized access to computers and the distribution of fraudulent communications, which applies to phishing schemes.
Wire Fraud Statute (18 U.S.C. § 1343): This law criminalizes schemes to defraud individuals or entities using electronic communications, including phishing.
CAN-SPAM Act (15 U.S.C. § 7701): This act regulates commercial email and prohibits misleading headers and deceptive subject lines, relevant to phishing domains.
Regulatory Note: Failure to take immediate action against this domain may expose your organization to legal liability and regulatory scrutiny. Compliance with your AUP and TOS is essential to mitigate potential risks associated with hosting or registering domains involved in phishing activities.
Data Coverage
Ağ Güvenliği İstihbaratı
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| Cloudflare DNS | startiio.framer.media |
malicious | Sinkholed |
| DNS4EU | startiio.framer.media |
malicious | Sinkholed |
| OpenDNS | startiio.framer.media |
phishing | Phishing Block |
Tehdit Müdahale Pipeline
Engelleme listesi kapsamı
10 izlenen harici kaynak · kayıtlı anlık görüntü 13.08.2026
Tespit zaman çizelgesi
-
VirusTotal
12 → 18
Teknolojiler
4 yüksek güvenli teknoloji belirlendi
VirusTotal Analizi
Site Performans Analizi
Google PageSpeed Insights — mobile performance audit of startiio.framer.media · checked Jun 26, 2026
Bu Siteden Etkilendiniz mi?
Hesap kimlik bilgilerini, kişisel bilgileri veya ödeme bilgilerini girdiyseniz ya da bu alan adından bir dosya indirdiyseniz hemen harekete geçin. Aşağıda olayı bildirmenize ve kendinizi korumanıza yardımcı olacak kaynaklar bulunmaktadır.
Yerel Yetkililere Bildirin
resmi siber suç iletişim bilgileri veya şikayet taslağı oluştur → almak için ülkenizi seçin.
Herhangi Bir Alan Adını Kontrol Et
Saklanan engelleme listesi, WHOIS, DNS ve genel tarama kanıtlarını kullanarak tehdit analizi
Şimdi TaraOltalama Olayını Bildir
Şüpheli alan adlarını tehdit veritabanımıza bildirin — topluluğu koruyun
BildirCanlı Tehdit Akışı
Son kimlik avı raporları ve gözlemlenen kullanılabilirlik değişiklikleri
İzleGelişmelerden Haberdar Olun, Güvende Kalın
Canlı tehditleri izleyin veya bunun yanlış bir uyarı olduğunu düşünüyorsanız bu kayda itiraz edin