smtptelstrawebmailplusviewswifts[.]framer[.]website
“Sign in with your Telstra ID”
smtptelstrawebmailplusviewswifts.framer.website — Contenido no disponible (HTTP 404). Suplantación de marca: Telstra; Tipo de estafa: Credential Phishing. Resumen de las pruebas: VirusTotal 13/95 (ADMINUSLabs, alphaMountain.ai, BitDefender, CyRadar, ESET); URLQuery 100 det.; URLScan malicious verdict; Spamhaus DBL_PHISH; CF Radar malicious; PhishDestroy score 95/100. Registrador: CSC.
El análisis detallado de PhishDestroy AI se mantiene en inglés para conservar el registro forense original.
Technical Threat Report: smtptelstrawebmailplusviewswifts.framer.website
This site is a phishing page that impersonated the Telstra brand, presenting a login form titled "Sign in with your Telstra ID." The threat posed is credential theft, targeting Telstra customers through an email-based scam. Users who entered their credentials on this page would have had their Telstra ID and password stolen by the threat actor.
Technical evidence confirms the malicious nature of the domain. VirusTotal analysis shows 13 out of 95 security vendors flagged the site as malicious, with detections from ADMINUSLabs, alphaMountain.ai, BitDefender, CyRadar, and ESET. The domain is registered with CSC Corporate Domains, Inc., was created on 2021-11-19, and resolves to IP address 35.71.142.77 in the United States, hosted on AS16509 (Amazon.com, Inc.). The site uses an SSL certificate issued by Let's Encrypt with fingerprint E7. Nameservers are ns-1243.awsdns-27.org, ns-1818.awsdns-35.co.uk, ns-336.awsdns-42.com, and ns-792.awsdns. The domain appears on two blocklists.
The site is currently offline and not accessible. However, the domain remains registered and could be reactivated. The risk level for users who previously visited and submitted credentials is high, as their Telstra login information is compromised. Telstra customers should change passwords immediately if they entered data on this page.
Inteligencia de seguridad de red
Proceso de respuesta ante amenazas Pipeline
Estado de la lista de bloqueados pública
Tecnologías · 4 identified
JavaScript library for building user interfaces with component-based architecture.
HTTP Strict Transport Security — forces browsers to use HTTPS connections only.
Third major version of HTTP protocol, built on QUIC for faster, more reliable connections.
Análisis de VirusTotal
Evidencias archivadas
Datos y informes externos
¿Te ha afectado esta página web?
Si ingresó credenciales de cuenta, información personal o de pago, o descargó un archivo de este dominio, tome medidas inmediatas. A continuación encontrará recursos que le ayudarán a informar el incidente y protegerse.
Informa a las autoridades locales
Seleccione su país para obtener contactos oficiales de cibercrimen o crear un borrador de queja →.
Comprobar cualquier dominio
Análisis de amenazas utilizando listas de bloqueo almacenadas, WHOIS, DNS y evidencia de escaneo público
Escanear ahoraDenunciar un intento de phishing
Envía los dominios sospechosos a nuestra base de datos de amenazas: protege a la comunidad
DenunciarFlujo de amenazas en tiempo real
Informes de phishing recientes y cambios de disponibilidad observados
MonitorizarMantente informado, mantente a salvo
Supervisa las amenazas en tiempo real o impugna esta entrada si crees que se trata de un falso positivo.