smtptelstrawebmailswiftviewtelstrawebmailswiftwebmail[.]framer[.]website
“Sign in with your Telstra ID”
smtptelstrawebmailswiftviewtelstrawebmailswiftwebmail.framer.website — सामग्री अनुपलब्ध (HTTP 404). ब्रांड प्रतिरूपण: Telstra; घोटाले का प्रकार: Credential Phishing. साक्ष्य सारांश: VirusTotal 13/95 (Criminal IP, alphaMountain.ai, BitDefender, CyRadar, ESET); URLQuery 100 det.; URLScan malicious verdict; Spamhaus DBL_PHISH; CF Radar malicious; PhishDestroy score 95/100. रजिस्ट्रार: CSC.
मूल फॉरेंसिक रिकॉर्ड सुरक्षित रखने के लिए नीचे का विस्तृत PhishDestroy AI विश्लेषण अंग्रेज़ी में रखा गया है।
Analysis of the domain smtptelstrawebmailswiftviewtelstrawebmailswiftwebmail.framer.website shows an active brand‑impersonation infrastructure that was taken offline prior to the report date of July 24, 2026. The domain was registered on November 19, 2021 through CSC Corporate Domains, Inc. and is hosted on Amazon Web Services, resolving to the IPv4 address 52.223.52.2, which belongs to AS16509 (Amazon.com, Inc.) and is geolocated in the United States. An SSL certificate issued by Let’s Encrypt (certificate identifier E7) was present, and the site advertised modern web technologies including Framer Sites, React, HTTP Strict Transport Security (HSTS) and HTTP/3 support. An HTTP request to the site returned a 404 status code, indicating that the landing page is no longer publicly reachable.
VirusTotal scans recorded 13 detections out of 95 security vendors, and the domain appears on a single public blocklist. PhishDestroy has also listed the domain as blocked. The page title observed during the brief capture phase was "Sign in with your Telstra ID," confirming the impersonation of Telstra and the credential‑phishing intent. Nameservers listed are ns-1243.awsdns-27.org, ns-1818.awsdns-35.co.uk, ns-336.awsdns-42.com and ns-792.awsdns, consistent with AWS DNS hosting.
While the site is currently offline, the persistence of the underlying AWS infrastructure and the reuse of the same certificate suggest the possibility of future reactivation. Defenders should add the IP address 52.223.52.2 to network deny lists, monitor DNS queries for the associated subdomains, and update email security gateways to block messages referencing the observed page title or the Telstra brand. Continuous surveillance of the registrar and blocklist entries is recommended to detect any re‑registration attempts or new hosting signatures tied to this campaign.
नेटवर्क सुरक्षा इंटेलिजेंस
धमकी प्रतिक्रिया पाइपलाइन
सार्वजनिक ब्लॉकलिस्ट स्थिति
तकनीकें · 4 identified
JavaScript library for building user interfaces with component-based architecture.
HTTP Strict Transport Security — forces browsers to use HTTPS connections only.
Third major version of HTTP protocol, built on QUIC for faster, more reliable connections.
वायरसटोटल विश्लेषण
संग्रहीत साक्ष्य
साक्ष्य और बाहरी रिपोर्टें
क्या आप इस साइट से प्रभावित हुए?
यदि आपने खाता क्रेडेंशियल, व्यक्तिगत या भुगतान जानकारी दर्ज की है, या इस डोमेन से कोई फ़ाइल डाउनलोड की है, तो तुरंत कार्रवाई करें। घटना की रिपोर्ट करने और अपनी सुरक्षा करने में आपकी सहायता के लिए नीचे संसाधन दिए गए हैं।
अपने स्थानीय अधिकारियों को रिपोर्ट करें
आधिकारिक साइबर अपराध संपर्क, या एक शिकायत ड्राफ्ट बनाएं → प्राप्त करने के लिए अपना देश चुनें।
किसी भी डोमेन की जाँच करें
संग्रहीत ब्लॉकलिस्ट, WHOIS, DNS और सार्वजनिक स्कैन साक्ष्य का उपयोग करके खतरे का विश्लेषण
अभी स्कैन करेंफ़िशिंग की रिपोर्ट करें
संदिग्ध डोमेन हमारे थ्रेट डेटाबेस में जमा करें — समुदाय की सुरक्षा करें
रिपोर्ट करेंसीधा खतरा फीड
हाल की फ़िशिंग रिपोर्टें और उपलब्धता में परिवर्तन देखे गए
निगरानी करेंजानकारी में रहें, सुरक्षित रहें
लाइव खतरों की निगरानी करें या यदि आपको लगता है कि यह एक गलत सकारात्मक है तो इस लिस्टिंग को चुनौती दें।