en-phantm-app[.]framer[.]ai
“Site Not Found | Framer”
en-phantm-app.framer.ai — Контент недоступний. Уособлення бренду: Phantom; Тип шахрайства: Wallet/seed Phishing. Зведення доказів: VirusTotal 1/95 (ChainPatrol); PhishDestroy score 55/100. Реєстратор: CSC.
Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.
The domain en-phantm-app.framer.ai is presently offline but exhibits several indicators consistent with a targeted brand impersonation campaign aimed at the cryptocurrency wallet Phantom. Registration data shows the domain was created on January 06, 2018 through CSC Corporate Domains, Inc., and it resolves to the Amazon Web Services IP address 52.223.52.2, which is owned by AS16509 Amazon.com, Inc. The site serves a default Framer page titled "Site Not Found | Framer" and returns an HTTP 404 status, which suggests the malicious content has been removed or the infrastructure has been taken down. Despite the current offline state, the domain appears on at least one security blocklist and has been explicitly blocked by PhishDestroy, confirming its association with phishing activity.
The SSL certificate presented is a Let's Encrypt certificate (E8), indicating the use of a freely issued TLS credential common among illicit operators to lend legitimacy to phishing sites. Technical fingerprints include Framer Sites, React, HSTS, and HTTP/3, all of which are typical of modern web hosting stacks and do not, by themselves, indicate malicious intent but corroborate the environment used for the campaign. VirusTotal analysis shows that one of ninety‑five security vendors flagged the domain, providing an additional data point of suspicion.
The page title and the listed scam type, "Wallet/Seed Phishing," directly link the domain to attempts at harvesting Phantom wallet seed phrases. Defenders should continue to monitor the IP address 52.223.52.2 for any re‑activation of malicious services, enforce blocklisting of the domain in corporate web filters, and include the associated nameservers (ns-114.awsdns-14.com, ns-1198.awsdns-21.org, ns-1902.awsdns-45.co.uk, ns-635.awsdns) in any DNS‑based threat intelligence feeds.
Процес реагування на загрози Pipeline
Статус у публічних блоклистах
Технології · 4 identified
JavaScript library for building user interfaces with component-based architecture.
HTTP Strict Transport Security — forces browsers to use HTTPS connections only.
Third major version of HTTP protocol, built on QUIC for faster, more reliable connections.
Аналіз VirusTotal
Архівні докази
Докази та зовнішні звіти
Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога