navi-kraken-web[.]framer[.]media
“Site Not Found | Framer”
navi-kraken-web.framer.media — 内容不可用. 品牌冒充:Kraken; 诈骗类型:Crypto Scam. 证据摘要: VirusTotal 13/95 (ChainPatrol, alphaMountain.ai, BitDefender, CRDF, CyRadar); URLQuery 2 alerts; Google Safe Browsing flagged; PhishDestroy score 89/100. 注册商: CSC.
为保留原始取证记录,下方的 PhishDestroy AI 详细分析仍使用英文。
Analysis of navi-kraken-web.framer.media, first observed after registration on 21 February 2026, indicates that the domain was used to host a fraudulent page impersonating the cryptocurrency exchange Kraken. The site resolved to the Amazon Web Services IP address 35.71.142.77, which belongs to AS16509 (Amazon.com, Inc.) and is physically located in the United States. DNS resolution was provided by the four AWS‑hosted name servers ns-97.awsdns-12.com, ns-1854.awsdns-39.co.uk, ns-535.awsdns-02.net, and ns-1 (truncated in the source). The web server presented a Let’s Encrypt certificate issued under the E7 identifier, and the connection employed HSTS and HTTP/3, consistent with modern web frameworks. Technology fingerprinting identified Framer Sites and a React front‑end, confirming that the page was generated with the Framer web‑design platform.
Google Safe Browsing flagged the URL for social engineering, and PhishDestroy added the domain to its blocklist, resulting in a single security blocklist entry at the time of reporting. VirusTotal scans returned 13 positive detections out of 95 vendors, reinforcing the malicious classification. The HTTP response returned a 404 status code with the page title “Site Not Found | Framer”, suggesting that the content was removed or taken offline. The registrar listed for the domain is CSC Corporate Domains, Inc., a bulk registrar often leveraged for rapid domain acquisition.
The available evidence points to a crypto‑related scam that sought to exploit Kraken’s brand reputation, although the exact payload or credential‑harvesting mechanism has not been captured. Because the site is currently offline, active mitigation is limited to ensuring that the domain remains listed on blocklists and that endpoint protection solutions continue to recognize the 13 VirusTotal detections. Defenders should monitor for re‑registration of the domain or the appearance of similar sub‑domains under the framer.
网络安全情报
威胁响应 Pipeline
公共封禁名单状态
所用技术 · 4 identified
Framer is a no-code web design platform for designing and publishing responsive websites.
www.framer.com 置信度 100%React is an open-source JavaScript library for building user interfaces or UI components.
reactjs.org 置信度 100%HTTP Strict Transport Security (HSTS) informs browsers that the site should only be accessed using HTTPS.
www.rfc-editor.org 置信度 100%HTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org 置信度 100%VirusTotal 分析
网站性能分析
Google PageSpeed Insights — mobile performance audit of navi-kraken-web.framer.media · checked Mar 2, 2026
证据与外部报告
您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。