ndaxio[.]framer[.]media
Verifica phishing e sicurezza per ndaxio.framer.media
“Log In | Ndax™(En-Us)”
ndaxio.framer.media — Contenuto non disponibile (HTTP 404). Simulazione del marchio: Ndax; Tipo di truffa: Credential Phishing. Riepilogo delle prove: VT 18/95 (ADMINUSLabs, alphaMountain.ai, Cluster25, CRDF, CyRadar); URLQuery 0; URLScan malicious; GSB no flag; BL 0; CF Radar malicious; PD 95/100. Registrar: CSC.
L’analisi dettagliata di PhishDestroy AI resta in inglese per preservare il rapporto forense originale.
ndaxio.framer.media is a tenant hostname on CSC Corporate Domains, Inc., not a separately registered domain. PhishDestroy first recorded this hostname on Jan 26, 2026. The hostname explicitly references Ndax; stored content metadata identifies the same apparent target. The stored content classification is credential phishing. The assembled evidence scores 95/100 (critical).
Three independent sources are positive: VirusTotal, Cloudflare Radar, and URLScan. VirusTotal recorded 18 detections among 95 engines: ADMINUSLabs, alphaMountain.ai, Cluster25, CRDF, CyRadar, DNS8, ESET, Emsisoft, Forcepoint ThreatSeeker, Fortinet, Gridinsoft, Kaspersky, Lionic, Netcraft, Sophos, Trustwave, VIPRE, Webroot on Jul 18, 2026 at 18:45 UTC. Cloudflare Radar classified the hostname as malicious and assigned the categories phishing and security threats; its verdict timestamp was not retained. URLScan returned a malicious verdict with score 100 on Mar 27, 2026 at 12:01 UTC. The evidence is not unanimous. The external blocklist snapshot contained no matches on Aug 7, 2026 at 18:20 UTC. URLQuery recorded no positive detection. Google Safe Browsing returned no flag on Mar 3, 2026 at 04:14 UTC. PhishStats returned no feed match on Mar 1, 2026 at 16:06 UTC.
HTTP 404 was recorded on Aug 7, 2026 at 01:05 UTC; content was unavailable. CSC Corporate Domains, Inc. is the hosting platform for this tenant, not its registrar. At collection time, the hostname resolved to 52.223.52.2 on AS16509 (AMAZON-02 - Amazon.com, Inc., US). The associated network metadata labels the endpoint as AS16509 Amazon.com, Inc. in Seattle, US. This is shared platform infrastructure; the IP and ASN are hosting context, not attribution to unrelated tenants. The stored server header is Framer/cc95054. Captured page title: “Log In | Ndax™(En-Us)”. DOM analysis completed on Jul 29, 2026 at 04:12 UTC; stored DOM score 5/100. The evidence archive retains 2 visual captures from PhishDestroy and URLScan. IoC extraction completed on Aug 2, 2026 at 04:15 UTC; stored 0 format-validated wallet addresses and 0 Telegram indicators. The platform TLS certificate was issued by Let's Encrypt / E7 with validity through May 18, 2026; checked Mar 15, 2026 at 05:42 UTC.
Taken together, the page content and independent findings support classifying this hostname as Ndax-themed credential phishing.
Informazioni sulla sicurezza di rete
Pipeline di risposta alle minacce
Stato della lista di blocco pubblica
Tecnologie · 4 identified
Framer is a no-code web design platform for designing and publishing responsive websites.
www.framer.com Confidenza al 100%React is an open-source JavaScript library for building user interfaces or UI components.
reactjs.org Confidenza al 100%HTTP Strict Transport Security (HSTS) informs browsers that the site should only be accessed using HTTPS.
www.rfc-editor.org Confidenza al 100%HTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org Confidenza al 100%Analisi di VirusTotal
Prove archiviate
Dati e relazioni esterne
Questo sito ti ha influenzato in qualche modo?
Se hai inserito credenziali dell'account, informazioni personali o di pagamento oppure hai scaricato un file da questo dominio, agisci immediatamente. Di seguito sono riportate le risorse per aiutarti a segnalare l'incidente e proteggerti.
Segnalalo alle autorità locali
Seleziona il tuo Paese per ottenere contatti ufficiali del crimine informatico o creare una bozza di reclamo →.
Verifica qualsiasi dominio
Analisi delle minacce utilizzando blocklist archiviate, WHOIS, DNS e prove di scansione pubblica
Scansiona oraSegnala un tentativo di phishing
Segnala i domini sospetti al nostro database delle minacce — proteggi la comunità
SegnalaFeed in tempo reale sulle minacce
Segnalazioni recenti di phishing e modifiche osservate della disponibilità
MonitoraRimani informato, rimani al sicuro
Controlla le minacce in tempo reale oppure contesta questa segnalazione se ritieni che si tratti di un falso positivo