suite-en[.]framer[.]ai
“Connect & Find Your Trezor”
suite-en.framer.ai — 内容不可用. 品牌冒充:Trezor; 诈骗类型:Crypto Scam. 证据摘要: VirusTotal 10/95 (alphaMountain.ai, CyRadar, ESET, Forcepoint ThreatSeeker, Fortinet); URLScan malicious verdict; CF Radar malicious; PhishDestroy score 80/100. 注册商: CSC.
为保留原始取证记录,下方的 PhishDestroy AI 详细分析仍使用英文。
On July 25, 2026, the domain suite-en.framer.ai was observed offline and is currently listed by PhishDestroy as a malicious site that impersonates the cryptocurrency hardware‑wallet brand Trezor. The site’s page title, “Connect & Find Your Trezor,” directly references the target brand, confirming a brand‑impersonation tactic. Registry data shows the domain was registered on 6 January 2018 through CSC Corporate Domains, Inc. The hosting resolves to the IP address 64.29.17.195, which belongs to Amazon.com, Inc. (AS16509) and is geolocated in the United States. DNS resolution uses four Amazon Route 53 nameservers: ns-114.awsdns-14.com, ns-1198.awsdns-21.org, ns-1902.awsdns-45.co.uk, and ns-635.awsdns. The TLS certificate is issued by Let’s Encrypt (E8), and the site advertised HSTS and HTTP/3 support.
A technology fingerprint identified Framer Sites and React, consistent with a modern front‑end stack. When queried, the HTTP response returned a 404 status code, indicating the content is not being served at the time of check. VirusTotal analysis returned 10 detections out of 95 scanners, and the domain appears on a single external blocklist, reinforcing its malicious classification. The threat is categorized as a “Crypto Scam,” suggesting the actors may attempt to harvest credentials or lure victims into fraudulent crypto‑related transactions. The presence of a valid TLS certificate does not mitigate risk, as encrypted channels are routinely used by malicious actors to gain user trust.
Uncertainties remain regarding the current payload or credential‑capture mechanisms because the site is offline and no page content was captured. Defenders should continue to block the domain at network perimeters, update DNS filtering policies, and ensure that endpoint protection solutions incorporate the latest indicator set, including the domain name, its IP address, and the associated nameservers.
网络安全情报
威胁响应 Pipeline
公共封禁名单状态
所用技术 · 4 identified
JavaScript library for building user interfaces with component-based architecture.
HTTP Strict Transport Security — forces browsers to use HTTPS connections only.
Third major version of HTTP protocol, built on QUIC for faster, more reliable connections.
VirusTotal 分析
存档证据
证据与外部报告
您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。