trzor-suiit-es[.]framer[.]ai
“Official Trézor Suite — Desktop & Web App for Hardware”
trzor-suiit-es.framer.ai — 内容不可用. 品牌冒充:Sui; 诈骗类型:Seed Phrase Theft. 证据摘要: VirusTotal 4/91 (ChainPatrol, Forcepoint ThreatSeeker, Kaspersky, PhishFort); URLScan malicious verdict; Spamhaus DBL_ABUSED_PHISH; 2 external blocklist matches (MetaMask, SEAL); PhishDestroy score 66/100. 注册商: CSC.
为保留原始取证记录,下方的 PhishDestroy AI 详细分析仍使用英文。
This domain, trzor-suiit-es.framer.ai, is currently under investigation for operating as a cryptocurrency phishing site designed to impersonate the official Trezor Suite platform. Analysis indicates the site presents itself as the legitimate desktop and web application for Trezor hardware wallets, a well-known cryptocurrency storage solution. The threat type is classified as brand impersonation phishing, specifically targeting users attempting to access their crypto wallets through fraudulent login interfaces. Infrastructure analysis reveals the domain was registered on January 6, 2018, through CSC Corporate Domains, Inc., though recent activity suggests it has been repurposed for malicious use. The domain resolves to the IP address 31.43.161.6 and currently shows 0 detections out of 95 vendors on VirusTotal, indicating it has not yet been widely flagged by security providers. The SSL certificate is issued by Let’s Encrypt, a common practice among both legitimate and malicious sites to encrypt traffic and evade basic scrutiny. No blocklist entries or trust score downgrades were identified at the time of this report, though the domain remains active and accessible. The risk posed by this infrastructure is considered elevated due to its direct targeting of cryptocurrency users, a high-value demographic for financial fraud. Users who interact with the site may inadvertently expose wallet credentials, recovery seeds, or other sensitive authentication details, leading to unauthorized access and asset theft. Organizations and individuals are advised to block access to the domain at the network level and monitor for related indicators of compromise, including the IP address 31.43.161.6. End users should verify the authenticity of any Trezor Suite-related domain by cross-referencing with official sources and avoid entering credentials on untrusted platforms. Security teams are encouraged to submit the domain to additional threat intelligence platforms for broader detection and mitigation.
威胁响应 Pipeline
公共封禁名单状态
所用技术 · 5 identified
Framer is a no-code web design platform for designing and publishing responsive websites.
www.framer.com 置信度 100%React is an open-source JavaScript library for building user interfaces or UI components.
reactjs.org 置信度 100%HTTP Strict Transport Security (HSTS) informs browsers that the site should only be accessed using HTTPS.
www.rfc-editor.org 置信度 100%Google Analytics is a free web analytics service that tracks and reports website traffic.
google.com 置信度 100%HTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org 置信度 100%VirusTotal 分析
存档证据
网站性能分析
Google PageSpeed Insights — mobile performance audit of trzor-suiit-es.framer.ai · checked Jun 29, 2026
证据与外部报告
PD-20260629-984EAD Recipient: abuse@framer.com 您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。