ndaxio[.]framer[.]media
Análisis de phishing y seguridad de ndaxio.framer.media
“Log In | Ndax™(En-Us)”
ndaxio.framer.media — Contenido no disponible (HTTP 404). Suplantación de marca: Ndax; Tipo de estafa: Credential Phishing. Resumen de las pruebas: VT 18/95 (ADMINUSLabs, alphaMountain.ai, Cluster25, CRDF, CyRadar); URLQuery 0; URLScan malicious; GSB no flag; BL 0; CF Radar malicious; PD 95/100. Registrador: CSC.
El análisis detallado de PhishDestroy AI se mantiene en inglés para conservar el registro forense original.
ndaxio.framer.media is a tenant hostname on CSC Corporate Domains, Inc., not a separately registered domain. PhishDestroy first observed the hostname on Jan 26, 2026. The hostname explicitly references Ndax; stored content metadata identifies the same apparent target. The captured page title is “Log In | Ndax™(En-Us)”. Stored page analysis classifies the content as credential phishing. Current evidence score: 95/100 (critical).
Positive findings are stored from 3 sources: VirusTotal, Cloudflare Radar, and URLScan. VirusTotal recorded 18 detections among 95 engines: ADMINUSLabs, alphaMountain.ai, Cluster25, CRDF, CyRadar, DNS8, ESET, Emsisoft, Forcepoint ThreatSeeker, Fortinet, Gridinsoft, Kaspersky, Lionic, Netcraft, Sophos, Trustwave, VIPRE, Webroot on Jul 18, 2026 at 18:45 UTC. Cloudflare Radar classified the hostname as malicious and assigned the categories phishing and security threats; its verdict timestamp was not retained. URLScan returned a malicious verdict with score 100; scan metadata assigned phishing as its category on Jul 29, 2026 at 03:27 UTC. Non-positive and contextual checks: The external blocklist snapshot contained no matches on Aug 8, 2026 at 02:20 UTC. URLQuery recorded no positive detection; no observation timestamp was retained. Google Safe Browsing returned no flag on Mar 3, 2026 at 04:14 UTC. PhishStats returned no feed match on Mar 1, 2026 at 16:06 UTC.
HTTP 404 was recorded on Aug 7, 2026 at 01:05 UTC; content was unavailable. CSC Corporate Domains, Inc. is the hosting platform for this tenant, not its registrar. At collection time, the hostname resolved to 52.223.52.2 on AS16509 (AMAZON-02 - Amazon.com, Inc., US). The recorded endpoint location is Seattle, US. The IP and ASN identify shared CSC Corporate Domains, Inc. infrastructure, not the tenant operator. The stored server header is Framer/cc95054. DOM analysis on Jul 29, 2026 at 04:12 UTC returned 5/100. The evidence archive retains 2 visual captures from PhishDestroy and URLScan. The platform TLS certificate was issued by Let's Encrypt / E7 with validity through May 18, 2026; checked Mar 15, 2026 at 05:42 UTC.
The content indicators and 3 positive source findings support the current Ndax-themed credential phishing classification.
Inteligencia de seguridad de red
Proceso de respuesta ante amenazas Pipeline
Estado de la lista de bloqueados pública
Tecnologías · 4 identified
Framer is a no-code web design platform for designing and publishing responsive websites.
www.framer.com 100 % de confianzaReact is an open-source JavaScript library for building user interfaces or UI components.
reactjs.org 100 % de confianzaHTTP Strict Transport Security (HSTS) informs browsers that the site should only be accessed using HTTPS.
www.rfc-editor.org 100 % de confianzaHTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org 100 % de confianzaAnálisis de VirusTotal
Evidencias archivadas
Datos y informes externos
¿Te ha afectado esta página web?
Si ingresó credenciales de cuenta, información personal o de pago, o descargó un archivo de este dominio, tome medidas inmediatas. A continuación encontrará recursos que le ayudarán a informar el incidente y protegerse.
Informa a las autoridades locales
Seleccione su país para obtener contactos oficiales de cibercrimen o crear un borrador de queja →.
Comprobar cualquier dominio
Análisis de amenazas utilizando listas de bloqueo almacenadas, WHOIS, DNS y evidencia de escaneo público
Escanear ahoraDenunciar un intento de phishing
Envía los dominios sospechosos a nuestra base de datos de amenazas: protege a la comunidad
DenunciarFlujo de amenazas en tiempo real
Informes de phishing recientes y cambios de disponibilidad observados
MonitorizarMantente informado, mantente a salvo
Supervisa las amenazas en tiempo real o impugna esta entrada si crees que se trata de un falso positivo.