multiple-teams-104491[.]framer[.]app
“Micro-soft Screen”
multiple-teams-104491.framer.app — Conteúdo indisponível. Representação da marca: Microsoft. Resumo das evidências: VirusTotal 18 detections (engine total unavailable) (alphaMountain.ai, BitDefender, Cluster25, CyRadar, ESET); URLQuery 4 alerts; URLScan malicious verdict; CF Radar malicious; PhishDestroy score 95/100. Registrador: Framer.
A análise detalhada do PhishDestroy AI permanece em inglês para preservar o registro forense original.
Domain multiple-teams-104491.framer.app functions as an active generic phishing site that impersonates Microsoft through a page titled Micro-soft Screen. The infrastructure leverages the Framer platform to host deceptive login interfaces designed to capture credentials from unsuspecting visitors. Analysis indicates the threat specifically targets users seeking Microsoft services by mimicking screen or account verification flows.
Technical indicators include a VirusTotal score of 16/95 security vendors flagging the domain, resolution to IP address 31.43.160.6, and registration through Framer. The site maintains active status with no recorded creation date or Google Safe Browsing block in available data. Infrastructure analysis reveals direct use of the Framer subdomain structure, which facilitates rapid deployment of phishing content without traditional domain registration footprints.
Current status remains active, sustaining high risk of credential theft for visitors. Recommended actions include immediate blocking at network perimeters, user notifications to avoid the domain, and reporting to hosting provider Framer for takedown. Residual exposure persists through similar subdomain patterns until the underlying account is suspended, requiring continued monitoring of Framer-hosted assets for parallel threats.
Inteligência de segurança de rede
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| Cloudflare DNS | multiple-teams-104491.framer.app |
malicious | Sinkholed |
| OpenDNS | multiple-teams-104491.framer.app |
phishing | Phishing Block |
| DNS4EU | multiple-teams-104491.framer.app |
malicious | Sinkholed |
| Quad9 DNS | multiple-teams-104491.framer.app |
malicious | Sinkholed |
Pipeline de resposta a ameaças
Status da lista de bloqueios pública
Tecnologias · 4 identified
Framer is a no-code web design platform for designing and publishing responsive websites.
www.framer.com 100% de confiançaReact is an open-source JavaScript library for building user interfaces or UI components.
reactjs.org 100% de confiançaHTTP Strict Transport Security (HSTS) informs browsers that the site should only be accessed using HTTPS.
www.rfc-editor.org 100% de confiançaHTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org 100% de confiançaAnálise do VirusTotal
Evidências e relatórios externos
PD-20260712-1195F2 Recipient: abuse@framer.com Você foi afetado por este site?
Se você inseriu credenciais de conta, informações pessoais ou de pagamento, ou baixou um arquivo deste domínio, tome medidas imediatas. Abaixo estão os recursos para ajudá-lo a relatar o incidente e se proteger.
Notifique as autoridades locais
Selecione seu país para obter contactos oficiais do cibercrime ou crie um rascunho de reclamação →.
Verificar qualquer domínio
Análise de ameaças usando lista de bloqueio armazenada, WHOIS, DNS e evidências de verificação pública
Digitalize agoraDenunciar phishing
Envie domínios suspeitos para nosso banco de dados de ameaças — proteja a comunidade
DenunciarFeed de ameaças em tempo real
Relatórios recentes de phishing e alterações de disponibilidade observadas
MonitorarMantenha-se informado, mantenha-se seguro
Monitore ameaças em tempo real ou conteste esta listagem caso acredite que se trate de um falso positivo