trezsuiteapp-enus[.]framer[.]ai
“My Framer Site”
trezsuiteapp-enus.framer.ai — İçerik kullanılamıyor. Marka kimliğine bürünme: Sui; Dolandırıcılık türü: Credential Phishing. Kanıt özeti: VirusTotal 5/91 (ChainPatrol, Fortinet, G-Data, Kaspersky, Sophos); URLScan malicious verdict; 2 external blocklist matches (MetaMask, SEAL); PhishDestroy score 66/100. Kayıt kuruluşu: CSC.
Özgün adli kaydı korumak için aşağıdaki ayrıntılı PhishDestroy AI analizi İngilizce bırakılmıştır.
This domain, trezsuiteapp-enus.framer.ai, is actively engaged in credential harvesting operations targeting users of the Framer platform. The site presents a deceptive interface designed to mimic legitimate Framer authentication portals, tricking users into submitting login credentials, API keys, or other sensitive account information. Analysis of the page structure reveals input fields for email addresses and passwords, along with visual elements consistent with Framer’s branding, indicating a targeted impersonation campaign. Infrastructure analysis reveals multiple technical indicators supporting the malicious classification. The domain resolves to IP address 31.43.160.6 and was registered on January 6, 2018, through CSC Corporate Domains, Inc. Despite its age, the domain has only been flagged by 2 out of 95 security vendors on VirusTotal, suggesting either recent activation for malicious purposes or effective evasion techniques. The SSL certificate is issued by Let’s Encrypt, providing HTTPS encryption to lend an appearance of legitimacy while failing to prevent credential interception. No entries were found on major blocklists at the time of analysis, further complicating detection efforts. Users who have visited trezsuiteapp-enus.framer.ai or entered credentials on the site should immediately revoke any exposed passwords and API keys. Reset credentials for all accounts where the same password may have been reused, particularly Framer and associated email accounts. Monitor linked accounts for unauthorized access attempts, and enable multi-factor authentication where available. Security teams should block the domain and IP address 31.43.160.6 at the network perimeter, and inspect logs for connections to either indicator. If credentials were submitted, assume full account compromise and conduct a forensic review of recent activity for signs of lateral movement or data exfiltration.
Tehdit Müdahale Pipeline
Genel Engelleme Listesi Durumu
VirusTotal Analizi
Arşivlenmiş Kanıtlar
Site Performans Analizi
Google PageSpeed Insights — mobile performance audit of trezsuiteapp-enus.framer.ai · checked Jun 26, 2026
Kanıtlar ve Dış Raporlar
PD-20260626-BC9270 Recipient: abuse@framer.com Bu Siteden Etkilendiniz mi?
Hesap kimlik bilgilerini, kişisel bilgileri veya ödeme bilgilerini girdiyseniz ya da bu alan adından bir dosya indirdiyseniz hemen harekete geçin. Aşağıda olayı bildirmenize ve kendinizi korumanıza yardımcı olacak kaynaklar bulunmaktadır.
Yerel Yetkililere Bildirin
resmi siber suç iletişim bilgileri veya şikayet taslağı oluştur → almak için ülkenizi seçin.
Herhangi Bir Alan Adını Kontrol Et
Saklanan engelleme listesi, WHOIS, DNS ve genel tarama kanıtlarını kullanarak tehdit analizi
Şimdi TaraOltalama Olayını Bildir
Şüpheli alan adlarını tehdit veritabanımıza bildirin — topluluğu koruyun
BildirCanlı Tehdit Akışı
Son kimlik avı raporları ve gözlemlenen kullanılabilirlik değişiklikleri
İzleGelişmelerden Haberdar Olun, Güvende Kalın
Canlı tehditleri izleyin veya bunun yanlış bir uyarı olduğunu düşünüyorsanız bu kayda itiraz edin