newcomer-wheel-891736[.]framer[.]app
“newcomer-wheel-891736.framer.app”
newcomer-wheel-891736.framer.app — Контент недоступний. Уособлення бренду: Trezor. Зведення доказів: VirusTotal 13/91 (ChainPatrol, alphaMountain.ai, BitDefender, CyRadar, Emsisoft); 2 external blocklist matches (MetaMask, SEAL); CF Radar malicious; PhishDestroy score 94/100. Реєстратор: Framer.
Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.
This domain, newcomer-wheel-891736.framer.app, represents a confirmed brand impersonation threat specifically targeting users of a widely recognized cryptocurrency hardware wallet. The site presents itself as the official management application, using the page title 'Trezor Suite | Official Crypto Management App' to deceive visitors into entering sensitive credentials, recovery phrases, or private keys. Such impersonation attacks are designed to exfiltrate cryptographic secrets, enabling unauthorized access to digital assets stored in user wallets. The high-risk nature of this threat is amplified by its active status and the critical sensitivity of the targeted information. Analysis of the domain's infrastructure reveals several concerning indicators. The domain resolves to the IP address 31.43.160.6 and is hosted on a platform that provides subdomains under framer.app, a legitimate service often abused for phishing campaigns. According to aggregated threat intelligence, 5 out of 95 security vendors on VirusTotal have flagged this domain as malicious, indicating emerging but not yet widespread detection. The SSL certificate is issued by Let's Encrypt, a common provider for both legitimate and malicious sites, which does not mitigate the risk. No specific registrar or creation date is publicly available for this subdomain, but the hosting pattern aligns with known phishing tactics leveraging free or low-cost platforms to evade initial scrutiny. Users who have visited newcomer-wheel-891736.framer.app or interacted with its content are advised to take immediate corrective actions. First, cease all interaction with the domain and avoid entering any credentials or sensitive information. If any data was submitted, assume it has been compromised and initiate recovery protocols for the affected wallet, including generating new recovery phrases and transferring assets to a new, secure wallet. Monitor all associated accounts for unauthorized transactions and enable additional authentication measures where available. Report the domain to relevant security teams and blocklist providers to aid in broader mitigation efforts. Regularly update security tools to ensure detection of similar threats in the future.
Розвіддані з мережевої безпеки
Процес реагування на загрози Pipeline
Статус у публічних блоклистах
Технології · 4 identified
Framer is a no-code web design platform for designing and publishing responsive websites.
www.framer.com 100% впевненостіReact is an open-source JavaScript library for building user interfaces or UI components.
reactjs.org 100% впевненостіHTTP Strict Transport Security (HSTS) informs browsers that the site should only be accessed using HTTPS.
www.rfc-editor.org 100% впевненостіHTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org 100% впевненостіАналіз VirusTotal
Архівні докази
Аналіз продуктивності сайту
Google PageSpeed Insights — mobile performance audit of newcomer-wheel-891736.framer.app · checked Jun 29, 2026
Докази та зовнішні звіти
PD-20260629-09B44D Recipient: abuse@framer.com Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога