telstrawebmailautoau[.]framer[.]website
“Sign in with your Telstra ID”
Analysis of telstrawebmailautoau.framer.website shows a credential‑phishing campaign that impersonates Telstra. The domain was registered on 19 November 2021 through CSC Corporate Domains, Inc., and is hosted on Amazon’s AS16509 network, resolving to 52.223.52.2 in the United States. DNS is served by four AWS Route 53 name servers (ns-1243.awsdns-27.org, ns-1818.awsdns-35.co.uk, ns-336.awsdns-42.com, ns-792.awsdns). The site runs Framer Sites with a React front end, enforces HSTS and supports HTTP/3, and presents the page title “Sign in with your Telstra ID”.
A Let’s Encrypt/E7 certificate secures the HTTPS endpoint, but the HTTP response is a 404, indicating the landing page is no longer reachable. The domain appears on a single security blocklist and has been flagged by PhishDestroy. VirusTotal scans show 12 of 93 AV engines flag the site as malicious, reinforcing the phishing classification. Current status is offline, suggesting takedown or removal by the hosting provider.
Evidence confirms Telstra brand impersonation and credential‑phishing intent, but the exact phishing payload and any harvested credentials remain unverified. Defenders should continue to block the domain at network perimeter, monitor for related C2 infrastructure tied to the same IP range, and update email filtering rules to catch similar “Sign in with your Telstra ID” subject lines. Further investigation of any residual DNS records or associated subdomains is recommended to ensure complete remediation.
Network Security Intelligence
Threat Response Pipeline
Public Blocklist Status
Technologies · 4 identified
JavaScript library for building user interfaces with component-based architecture.
HTTP Strict Transport Security — forces browsers to use HTTPS connections only.
Third major version of HTTP protocol, built on QUIC for faster, more reliable connections.
VirusTotal Analysis
Archived Evidence
Evidence & External Reports
Were You Affected by This Site?
If credentials, payment data, or files were exposed, report the incident immediately. Change affected passwords, revoke active sessions, and scan the device.
Report to Your Local Authorities
Select your country to get official cybercrime contacts, or create a complaint draft →.
Check Any Domain
Threat analysis using stored blocklist, WHOIS, DNS, and public scan evidence
Scan NowReport Phishing
Submit suspicious domains to our threat database — protect the community
ReportLive Threat Feed
Recent phishing reports and observed availability changes
MonitorStay Informed, Stay Safe
Monitor live threats or contest this listing if you believe it's a false positive