phantomwallett--secures[.]framer[.]ai
“Site Not Found | Framer”
phantomwallett--secures.framer.ai — 内容不可用. 品牌冒充:Phantom; 诈骗类型:Crypto Scam. 证据摘要: VirusTotal 1/95 (ChainPatrol); PhishDestroy score 55/100. 注册商: CSC.
为保留原始取证记录,下方的 PhishDestroy AI 详细分析仍使用英文。
Analysis of the domain phantomwallett--secures.framer.ai shows a clear alignment with a brand‑impersonation campaign targeting Phantom users. The site is hosted on Amazon Web Services (AS16509) in the United States and resolves to IP address 35.71.142.77. The domain was registered on 6 January 2018 through CSC Corporate Domains, Inc., and it employs a Let’s Encrypt certificate (issuer E8) that provides TLS encryption and HSTS enforcement. Technical fingerprinting reveals the use of Framer Sites, React, and HTTP/3, confirming that the infrastructure is built on a modern web‑app stack rather than a static phishing landing page.
The domain is served by four AWS Route 53 nameservers (ns-114.awsdns-14.com, ns-1198.awsdns-21.org, ns-1902.awsdns-45.co.uk, ns-635.awsdns). HTTP requests return a 404 status code and the page title is “Site Not Found | Framer,” indicating that the content has been removed or the site is deliberately taken offline. Despite the removal, the domain remains listed on at least one security blocklist and is flagged by PhishDestroy, providing external confirmation of malicious intent. VirusTotal reports a single detection out of ninety‑five scanners, reinforcing the suspicion without establishing a definitive verdict.
The known scam type is a crypto‑related impersonation, but the exact payload or credential‑harvesting mechanism has not been captured. Defenders should continue to block the hostname and associated IP address at network perimeter devices, monitor DNS queries for the listed nameservers, and add the domain to internal threat‑intel feeds. Because the site is currently offline, ongoing surveillance is advised to detect any re‑activation or migration to new infrastructure.
威胁响应 Pipeline
公共封禁名单状态
所用技术 · 4 identified
JavaScript library for building user interfaces with component-based architecture.
HTTP Strict Transport Security — forces browsers to use HTTPS connections only.
Third major version of HTTP protocol, built on QUIC for faster, more reliable connections.
VirusTotal 分析
存档证据
证据与外部报告
您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。