renewed-communication-351741[.]framer[.]app
“Xfinity Sign In”
renewed-communication-351741.framer.app — Inhalt nicht verfügbar. Markenidentität: Microsoft; Betrugstyp: Tech Support Scam. Zusammenfassung der Beweislage: VirusTotal 20/93 (ADMINUSLabs, Criminal IP, alphaMountain.ai, BitDefender, Cluster25); URLScan malicious verdict; PhishDestroy score 95/100. Registrar: CSC.
Die ausführliche Analyse von PhishDestroy AI bleibt auf Englisch, damit der ursprüngliche forensische Bericht unverändert bleibt.
This domain, renewed-communication-351741.framer.app, was identified as a brand impersonation threat targeting Microsoft users through a deceptive login interface. The site presented itself as an Xfinity Sign In portal, a tactic commonly employed to harvest credentials by mimicking legitimate authentication pages. Such schemes often lead to unauthorized account access, data theft, or further malicious activity if users input sensitive information. Analysis indicates the domain was registered through CSC Corporate Domains, Inc. and resolved to the IP address 35.71.142.77, hosted on Amazon Web Services (AS16509). The domain was created on February 21, 2026, though its premature appearance suggests potential typosquatting or preemptive registration for malicious purposes. Detection systems flagged the domain on VirusTotal, with 20 out of 95 security vendors marking it as malicious. Additionally, it appeared on one security blocklist and was subsequently taken offline, though its infrastructure remains a potential indicator of compromise. Users who visited renewed-communication-351741.framer.app should immediately revoke any entered credentials, particularly for Microsoft or Xfinity accounts. Monitor linked accounts for unauthorized activity, such as password changes or unfamiliar transactions. If financial or personal data was submitted, consider reporting the incident to relevant authorities and implementing credit monitoring. Network administrators should update blocklists to include this domain and its associated IP (35.71.142.77) to prevent future access attempts. Always verify the authenticity of login pages by checking the URL and SSL certificate issuer (in this case, Let's Encrypt / E7) before entering credentials.
Pipeline zur Reaktion auf Sicherheitsbedrohungen
Status der öffentlichen Sperrliste
VirusTotal-Analyse
Archivierte Beweise
Nachweise und externe Berichte
Wurden Sie von dieser Website betroffen?
Wenn Sie Kontoanmeldeinformationen, persönliche oder Zahlungsinformationen eingegeben oder eine Datei von dieser Domain heruntergeladen haben, ergreifen Sie sofort Maßnahmen. Nachfolgend finden Sie Ressourcen, die Ihnen helfen, den Vorfall zu melden und sich zu schützen.
Melden Sie sich bei Ihren örtlichen Behörden
Wählen Sie Ihr Land aus, um Offizielle Kontakte im Bereich Cyberkriminalität oder einen Beschwerdeentwurf erstellen → zu erhalten.
Jede beliebige Domain prüfen
Bedrohungsanalyse anhand gespeicherter Blocklisten, WHOIS, DNS und öffentlicher Scan-Beweise
Jetzt scannenPhishing melden
Melden Sie verdächtige Domains an unsere Bedrohungsdatenbank – schützen Sie die Community
MeldenEchtzeit-Bedrohungsfeed
Aktuelle Phishing-Meldungen und beobachtete Verfügbarkeitsänderungen
ÜberwachenBleiben Sie auf dem Laufenden, bleiben Sie sicher
Beobachten Sie aktuelle Bedrohungen oder legen Sie Widerspruch gegen diesen Eintrag ein, wenn Sie der Meinung sind, dass es sich um einen Fehlalarm handelt