comcastlogin[.]framer[.]website
“Xfinity Sign In”
comcastlogin.framer.website — Contenuto non disponibile. Simulazione del marchio: Xfinity; Tipo di truffa: Credential Phishing. Riepilogo delle prove: VirusTotal 11/93 (Criminal IP, alphaMountain.ai, CyRadar, ESET, Forcepoint ThreatSeeker); URLQuery 100 det.; URLScan malicious verdict; Spamhaus DBL_PHISH; PhishDestroy score 95/100. Registrar: CSC.
L’analisi dettagliata di PhishDestroy AI resta in inglese per preservare il rapporto forense originale.
Analysis of comcastlogin.framer.website shows a credential‑phishing campaign that impersonates Xfinity. The site’s page title resolves to "Xfinity Sign In," directly matching the targeted brand. Technical fingerprinting indicates the site was built on the Framer Sites platform with a React front‑end, and it enforces HSTS while supporting HTTP/3, suggesting a modern web stack. The domain was registered on 19 November 2021 through CSC Corporate Domains, Inc., and uses four Amazon Route 53 name servers (ns-1243.awsdns-27.org, ns-1818.awsdns-35.co.uk, ns-336.awsdns-42.com, ns-792.awsdns). DNS resolution points to 52.223.52.2, an address owned by Amazon.com, Inc. (AS16509) located in the United States.
The TLS certificate is issued by Let’s Encrypt (E7), which is typical for short‑lived, low‑cost deployments. An HTTP request returns a 404 status, indicating the content is no longer publicly reachable; the current status is recorded as offline. Security‑vendor telemetry on VirusTotal shows 11 of 93 scanners flag the domain, and the URL appears on at least one active blocklist. PhishDestroy has also listed the site as blocked. These indicators collectively confirm the domain’s use for brand impersonation and credential harvesting.
Uncertainty remains around the exact content that was served before the site went offline, as the 404 response prevents direct inspection of the phishing page. Defenders should continue to block the domain at perimeter controls, monitor for any re‑hosting attempts on the same IP range, and add the URL to internal threat‑intel feeds. Given the Amazon hosting and Let’s Encrypt certificate, future iterations could be rapidly redeployed; therefore, automated detection rules that flag the combination of the Xfinity‑related page title and the Framer/React stack are recommended. Continuous observation of the registrar CSC Corporate Domains for new domains using similar naming patterns is also advised.
Pipeline di risposta alle minacce
Stato della lista di blocco pubblica
Tecnologie · 4 identified
JavaScript library for building user interfaces with component-based architecture.
HTTP Strict Transport Security — forces browsers to use HTTPS connections only.
Third major version of HTTP protocol, built on QUIC for faster, more reliable connections.
Analisi di VirusTotal
Prove archiviate
Dati e relazioni esterne
Questo sito ti ha influenzato in qualche modo?
Se hai inserito credenziali dell'account, informazioni personali o di pagamento oppure hai scaricato un file da questo dominio, agisci immediatamente. Di seguito sono riportate le risorse per aiutarti a segnalare l'incidente e proteggerti.
Segnalalo alle autorità locali
Seleziona il tuo Paese per ottenere contatti ufficiali del crimine informatico o creare una bozza di reclamo →.
Verifica qualsiasi dominio
Analisi delle minacce utilizzando blocklist archiviate, WHOIS, DNS e prove di scansione pubblica
Scansiona oraSegnala un tentativo di phishing
Segnala i domini sospetti al nostro database delle minacce — proteggi la comunità
SegnalaFeed in tempo reale sulle minacce
Segnalazioni recenti di phishing e modifiche osservate della disponibilità
MonitoraRimani informato, rimani al sicuro
Controlla le minacce in tempo reale oppure contesta questa segnalazione se ritieni che si tratti di un falso positivo