bright-elements-789228[.]framer[.]app
“My Framer Site”
bright-elements-789228.framer.app — सामग्री अनुपलब्ध. ब्रांड प्रतिरूपण: Microsoft; घोटाले का प्रकार: Tech Support Scam. साक्ष्य सारांश: VirusTotal 20/93 (ADMINUSLabs, Criminal IP, alphaMountain.ai, BitDefender, Cluster25); URLScan malicious verdict; CF Radar malicious; PhishDestroy score 95/100. रजिस्ट्रार: CSC.
मूल फॉरेंसिक रिकॉर्ड सुरक्षित रखने के लिए नीचे का विस्तृत PhishDestroy AI विश्लेषण अंग्रेज़ी में रखा गया है।
The domain bright-elements-789228.framer.app is identified as a brand impersonation threat specifically targeting Microsoft. Analysis confirms the domain is currently offline, though it previously hosted content designed to deceive users into believing it was an official Microsoft service. The page title, 'My Framer Site,' provides no legitimate branding context, further indicating malicious intent under the guise of a trusted entity. Infrastructure analysis reveals the domain was flagged by 20 of 95 security vendors on VirusTotal, reflecting a significant detection rate. It was registered through CSC Corporate Domains, Inc., and resolves to the IP address 35.71.142.77, hosted on Amazon.com, Inc. infrastructure (AS16509) in the United States. The domain's creation date is listed as February 21, 2026, which may indicate an attempt to evade temporal scrutiny or a typographical error in registration records. The SSL certificate is issued by Let's Encrypt (serial number E7), a common practice among threat actors to lend superficial legitimacy. The domain appears on one security blocklist and was actively blocked by PhishDestroy prior to being taken offline. Current status indicates the domain is no longer accessible, reducing immediate risk to end users. However, the infrastructure and registration patterns observed align with known brand impersonation tactics, particularly those targeting enterprise credentials. Organizations and individuals are advised to monitor for similar domains leveraging Framer's subdomain structure, as this vector remains actively exploited. Network administrators should update blocklists to include the resolved IP (35.71.142.77) and associated subdomains. Users who may have interacted with this domain should immediately reset credentials for any accounts accessed during the exposure window and enable multi-factor authentication where available. Proactive monitoring of certificate transparency logs for Let's Encrypt issuances tied to newly registered subdomains under framer.app may aid in early detection of similar threats.
नेटवर्क सुरक्षा इंटेलिजेंस
धमकी प्रतिक्रिया पाइपलाइन
सार्वजनिक ब्लॉकलिस्ट स्थिति
तकनीकें · 4 identified
Framer is a no-code web design platform for designing and publishing responsive websites.
www.framer.com 100% विश्वासReact is an open-source JavaScript library for building user interfaces or UI components.
reactjs.org 100% विश्वासHTTP Strict Transport Security (HSTS) informs browsers that the site should only be accessed using HTTPS.
www.rfc-editor.org 100% विश्वासHTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org 100% विश्वासवायरसटोटल विश्लेषण
संग्रहीत साक्ष्य
साक्ष्य और बाहरी रिपोर्टें
क्या आप इस साइट से प्रभावित हुए?
यदि आपने खाता क्रेडेंशियल, व्यक्तिगत या भुगतान जानकारी दर्ज की है, या इस डोमेन से कोई फ़ाइल डाउनलोड की है, तो तुरंत कार्रवाई करें। घटना की रिपोर्ट करने और अपनी सुरक्षा करने में आपकी सहायता के लिए नीचे संसाधन दिए गए हैं।
अपने स्थानीय अधिकारियों को रिपोर्ट करें
आधिकारिक साइबर अपराध संपर्क, या एक शिकायत ड्राफ्ट बनाएं → प्राप्त करने के लिए अपना देश चुनें।
किसी भी डोमेन की जाँच करें
संग्रहीत ब्लॉकलिस्ट, WHOIS, DNS और सार्वजनिक स्कैन साक्ष्य का उपयोग करके खतरे का विश्लेषण
अभी स्कैन करेंफ़िशिंग की रिपोर्ट करें
संदिग्ध डोमेन हमारे थ्रेट डेटाबेस में जमा करें — समुदाय की सुरक्षा करें
रिपोर्ट करेंसीधा खतरा फीड
हाल की फ़िशिंग रिपोर्टें और उपलब्धता में परिवर्तन देखे गए
निगरानी करेंजानकारी में रहें, सुरक्षित रहें
लाइव खतरों की निगरानी करें या यदि आपको लगता है कि यह एक गलत सकारात्मक है तो इस लिस्टिंग को चुनौती दें।