good-difference-990666[.]framer[.]app
“Lettre Recommandée Électronique AR24”
good-difference-990666.framer.app — सामग्री अनुपलब्ध. ब्रांड प्रतिरूपण: Ar24; घोटाले का प्रकार: Generic Phishing. साक्ष्य सारांश: VirusTotal 22/91 (ADMINUSLabs, alphaMountain.ai, BitDefender, Cluster25, CyRadar); URLQuery 4 alerts; URLScan malicious verdict; Google Safe Browsing flagged; CF Radar malicious; PhishDestroy score 95/100. रजिस्ट्रार: Framer.
मूल फॉरेंसिक रिकॉर्ड सुरक्षित रखने के लिए नीचे का विस्तृत PhishDestroy AI विश्लेषण अंग्रेज़ी में रखा गया है।
This domain is flagged as a high-risk phishing site specializing in credential harvesting through fraudulent electronic registered mail (Lettre Recommandée Électronique) lures targeting AR24 users. The page title, "Lettre Recommandée Électronique AR24," mimics legitimate postal notification services to deceive recipients into submitting sensitive login credentials or personal data. Analysis indicates the domain good-difference-990666.framer.app is registered through Framer and resolves to IP address 31.43.160.6, hosted on Amazon.com, Inc. infrastructure (AS16509) in the Netherlands. VirusTotal reports 22 out of 95 security vendors detecting the domain as malicious. The SSL certificate is issued by Let's Encrypt (identifier YE1), and the domain appears on one security blocklist. Google Safe Browsing has explicitly flagged the site as phishing. Current status shows the domain has been taken offline, though prior activity remains a concern. Mitigation steps for this threat type include blocking the domain and its resolving IP (31.43.160.6) at perimeter security controls. Network administrators should monitor for connections to this IP or related domains registered under Framer. End-users should be educated on recognizing phishing lures mimicking electronic registered mail services, particularly those impersonating AR24. If credentials were submitted, immediate password resets and multi-factor authentication enforcement are recommended. Logs should be reviewed for any prior interactions with the domain or IP to assess potential compromise.
नेटवर्क सुरक्षा इंटेलिजेंस
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| Cloudflare DNS | good-difference-990666.framer.app |
malicious | Sinkholed |
| OpenDNS | good-difference-990666.framer.app |
phishing | Phishing Block |
| DNS4EU | good-difference-990666.framer.app |
malicious | Sinkholed |
| Quad9 DNS | good-difference-990666.framer.app |
malicious | Sinkholed |
धमकी प्रतिक्रिया पाइपलाइन
सार्वजनिक ब्लॉकलिस्ट स्थिति
तकनीकें · 4 identified
Framer is a no-code web design platform for designing and publishing responsive websites.
www.framer.com 100% विश्वासReact is an open-source JavaScript library for building user interfaces or UI components.
reactjs.org 100% विश्वासHTTP Strict Transport Security (HSTS) informs browsers that the site should only be accessed using HTTPS.
www.rfc-editor.org 100% विश्वासHTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org 100% विश्वासवायरसटोटल विश्लेषण
साक्ष्य और बाहरी रिपोर्टें
PD-20260624-1B1718 Recipient: abuse@framer.com क्या आप इस साइट से प्रभावित हुए?
यदि आपने खाता क्रेडेंशियल, व्यक्तिगत या भुगतान जानकारी दर्ज की है, या इस डोमेन से कोई फ़ाइल डाउनलोड की है, तो तुरंत कार्रवाई करें। घटना की रिपोर्ट करने और अपनी सुरक्षा करने में आपकी सहायता के लिए नीचे संसाधन दिए गए हैं।
अपने स्थानीय अधिकारियों को रिपोर्ट करें
आधिकारिक साइबर अपराध संपर्क, या एक शिकायत ड्राफ्ट बनाएं → प्राप्त करने के लिए अपना देश चुनें।
किसी भी डोमेन की जाँच करें
संग्रहीत ब्लॉकलिस्ट, WHOIS, DNS और सार्वजनिक स्कैन साक्ष्य का उपयोग करके खतरे का विश्लेषण
अभी स्कैन करेंफ़िशिंग की रिपोर्ट करें
संदिग्ध डोमेन हमारे थ्रेट डेटाबेस में जमा करें — समुदाय की सुरक्षा करें
रिपोर्ट करेंसीधा खतरा फीड
हाल की फ़िशिंग रिपोर्टें और उपलब्धता में परिवर्तन देखे गए
निगरानी करेंजानकारी में रहें, सुरक्षित रहें
लाइव खतरों की निगरानी करें या यदि आपको लगता है कि यह एक गलत सकारात्मक है तो इस लिस्टिंग को चुनौती दें।