startedio-treze[.]framer[.]media
“Fix Trezor Device Not Connecting: Professional Support Analysis”
startedio-treze.framer.media — 内容不可用. 品牌冒充:Trezor; 诈骗类型:Brand Impersonation. 证据摘要: VirusTotal 12/91 (alphaMountain.ai, Cluster25, Fortinet, G-Data, Gridinsoft); URLQuery 4 alerts; URLScan malicious verdict; CF Radar malicious; PhishDestroy score 90/100. 注册商: CSC.
为保留原始取证记录,下方的 PhishDestroy AI 详细分析仍使用英文。
The domain startedio-treze.framer.media has been confirmed as a brand impersonation site targeting Trezor, a cryptocurrency hardware wallet provider. Analysis indicates this infrastructure was designed to deceive users by presenting itself as official Trezor support, specifically addressing device connectivity issues with the page title 'Fix Trezor Device Not Connecting: Professional Support Analysis.' The domain is currently offline, but prior activity suggests it was operational for malicious purposes, likely aiming to distribute crypto drainer malware or harvest sensitive credentials from unsuspecting victims seeking technical assistance. Infrastructure analysis reveals the domain was flagged by 16 of 95 security vendors on VirusTotal, indicating a high level of detection across multiple threat intelligence platforms. It appears on three security blocklists and is blocked by PhishDestroy, PhishingArmy, and OISD. The domain resolves to the IP address 31.43.161.6 and uses a Let's Encrypt SSL certificate for encrypted communications. Registration details point to CSC Corporate Domains, Inc. as the registrar. Technologies detected on the site include Framer Sites, React, HSTS, and HTTP/3, which are consistent with modern web development practices but do not mitigate the malicious intent of the infrastructure. The current offline status of startedio-treze.framer.media does not eliminate the risk posed by similar or resurfaced domains. Organizations and individuals are advised to implement strict blocklisting of this domain and its associated IP address in network security controls. Users who may have interacted with this domain should immediately revoke any connected wallet permissions, rotate credentials, and scan systems for malware. Cryptocurrency holders are reminded to verify official support channels directly through Trezor's authenticated domains and avoid engaging with unsolicited technical assistance offers, particularly those hosted on third-party platforms like Framer.
网络安全情报
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| Cloudflare DNS | startedio-treze.framer.media |
malicious | Sinkholed |
| OpenDNS | startedio-treze.framer.media |
phishing | Phishing Block |
| DNS4EU | startedio-treze.framer.media |
malicious | Sinkholed |
| Quad9 DNS | startedio-treze.framer.media |
malicious | Sinkholed |
威胁响应 Pipeline
公共封禁名单状态
所用技术 · 4 identified
Framer is a no-code web design platform for designing and publishing responsive websites.
www.framer.com 置信度 100%React is an open-source JavaScript library for building user interfaces or UI components.
reactjs.org 置信度 100%HTTP Strict Transport Security (HSTS) informs browsers that the site should only be accessed using HTTPS.
www.rfc-editor.org 置信度 100%HTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org 置信度 100%VirusTotal 分析
网站性能分析
Google PageSpeed Insights — mobile performance audit of startedio-treze.framer.media · checked Jun 26, 2026
证据与外部报告
PD-20260530-75ECF8 Recipient: abuse@framer.com 您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。