interactive-party-667481[.]framer[.]app
“Sign in to Xfinity”
증거 요약
This domain is flagged for hosting a fake login page impersonating Xfinity, a high-risk phishing threat targeting user credentials. Analysis indicates the page title explicitly mimics the legitimate "Sign in to Xfinity" portal, designed to deceive users into submitting sensitive authentication details. The domain presents an elevated risk due to its direct association with credential harvesting campaigns, a common precursor to account takeovers and identity fraud. Infrastructure analysis reveals the domain interactive-party-667481.framer.app was registered through Framer, a platform often abused for rapid phishing deployment. It resolved to the IP address 31.43.161.6, geolocated in the Netherlands under AS16509 (Amazon.com, Inc.), a hosting provider frequently leveraged for malicious infrastructure. At the time of assessment, the domain was offline, though it had been flagged by 18 out of 95 security vendors on VirusTotal, indicating broad detection across multiple threat intelligence sources. The domain appeared on at least one security blocklist, further corroborating its malicious classification. No creation date was provided, but the combination of registrar, IP reputation, and detection volume suggests a transient yet high-impact threat. Mitigation steps for this specific threat type include immediate blocking of the domain and its associated IP (31.43.161.6) at the network perimeter. Organizations should deploy email and web filtering rules to prevent delivery or access to URLs containing "interactive-party-667481.framer.app" or variations of the Framer subdomain structure. End users who may have interacted with the page should be instructed to reset credentials for any accounts entered, particularly those tied to Xfinity or other telecommunication services. Security teams are advised to monitor for follow-up phishing attempts using similar Framer-hosted domains, as threat actors frequently rotate infrastructure within the same registrar ecosystem. Credential monitoring and multi-factor authentication enforcement are recommended to mitigate potential account compromise.
제출된 증거 스냅샷
- 전송됨
- 원장 기록
- 1
- 사건 ID
PD-20260529-F19323- 캡처된 페이지 제목
- Sign in to Xfinity
- PDF 자료
- PDF 증거
증거 전문
Acceptable Use Policy (AUP): The domain interactive-party-667481.framer.app is actively engaged in phishing activities, which is a direct violation of your AUP prohibiting illegal activities, fraud, and deception.
Terms of Service (TOS): The ongoing use of this domain for fraudulent purposes constitutes a breach of your TOS, which reserves the right to suspend or terminate services for violations of policy.
Applicable Laws (Unknown):
Computer Fraud and Abuse Act (CFAA): This U.S. federal law prohibits unauthorized access to computers and the use of such access to commit fraud.
Wire Fraud Statute (18 U.S.C. § 1343): This law criminalizes schemes to defraud individuals or entities through electronic communications, including phishing.
CAN-SPAM Act (15 U.S.C. § 7701): This act regulates commercial email and prohibits deceptive practices in electronic communications, including phishing.
Regulatory Note: Failure to take immediate action against this domain may expose your organization to legal liability and regulatory scrutiny. It is imperative to comply with your AUP and TOS to mitigate potential risks.
Data Coverage
네트워크 보안 인텔리전스
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| OpenDNS | interactive-party-667481.framer.app |
phishing | Phishing Block |
| DNS4EU | interactive-party-667481.framer.app |
malicious | Sinkholed |
| Cloudflare DNS | interactive-party-667481.framer.app |
malicious | Sinkholed |
위협 대응 Pipeline
차단 목록 범위
모니터링 중인 외부 피드 10개 · 저장된 스냅샷 2026년 8월 13일
기술
신뢰도가 높은 기술 4개 식별
VirusTotal 분석
이 사이트로 인해 영향을 받으셨나요?
계정 자격 증명, 개인 정보 또는 결제 정보를 입력했거나 이 도메인에서 파일을 다운로드한 경우 즉시 조치를 취하세요. 다음은 사건을 신고하고 자신을 보호하는 데 도움이 되는 리소스입니다.
지역 당국에 신고하십시오
공식 사이버 범죄 연락처 또는 불만사항 초안 작성 →를 받으려면 국가를 선택하세요.
모든 도메인 확인
저장된 차단 목록, WHOIS, DNS 및 공개 스캔 증거를 사용한 위협 분석
지금 스캔하기피싱 신고
의심스러운 도메인을 당사의 위협 데이터베이스에 신고해 주세요 — 커뮤니티를 보호해 주세요
보고서실시간 위협 정보
최근 피싱 보고서 및 관찰된 가용성 변경 사항
모니터링