renewed-communication-351741[.]framer[.]app
“Xfinity Sign In”
renewed-communication-351741.framer.app — Conteúdo indisponível. Representação da marca: Microsoft; Tipo de golpe: Tech Support Scam. Resumo das evidências: VirusTotal 20/93 (ADMINUSLabs, Criminal IP, alphaMountain.ai, BitDefender, Cluster25); URLScan malicious verdict; PhishDestroy score 95/100. Registrador: CSC.
A análise detalhada do PhishDestroy AI permanece em inglês para preservar o registro forense original.
This domain, renewed-communication-351741.framer.app, was identified as a brand impersonation threat targeting Microsoft users through a deceptive login interface. The site presented itself as an Xfinity Sign In portal, a tactic commonly employed to harvest credentials by mimicking legitimate authentication pages. Such schemes often lead to unauthorized account access, data theft, or further malicious activity if users input sensitive information. Analysis indicates the domain was registered through CSC Corporate Domains, Inc. and resolved to the IP address 35.71.142.77, hosted on Amazon Web Services (AS16509). The domain was created on February 21, 2026, though its premature appearance suggests potential typosquatting or preemptive registration for malicious purposes. Detection systems flagged the domain on VirusTotal, with 20 out of 95 security vendors marking it as malicious. Additionally, it appeared on one security blocklist and was subsequently taken offline, though its infrastructure remains a potential indicator of compromise. Users who visited renewed-communication-351741.framer.app should immediately revoke any entered credentials, particularly for Microsoft or Xfinity accounts. Monitor linked accounts for unauthorized activity, such as password changes or unfamiliar transactions. If financial or personal data was submitted, consider reporting the incident to relevant authorities and implementing credit monitoring. Network administrators should update blocklists to include this domain and its associated IP (35.71.142.77) to prevent future access attempts. Always verify the authenticity of login pages by checking the URL and SSL certificate issuer (in this case, Let's Encrypt / E7) before entering credentials.
Pipeline de resposta a ameaças
Status da lista de bloqueios pública
Análise do VirusTotal
Evidências arquivadas
Evidências e relatórios externos
Você foi afetado por este site?
Se você inseriu credenciais de conta, informações pessoais ou de pagamento, ou baixou um arquivo deste domínio, tome medidas imediatas. Abaixo estão os recursos para ajudá-lo a relatar o incidente e se proteger.
Notifique as autoridades locais
Selecione seu país para obter contactos oficiais do cibercrime ou crie um rascunho de reclamação →.
Verificar qualquer domínio
Análise de ameaças usando lista de bloqueio armazenada, WHOIS, DNS e evidências de verificação pública
Digitalize agoraDenunciar phishing
Envie domínios suspeitos para nosso banco de dados de ameaças — proteja a comunidade
DenunciarFeed de ameaças em tempo real
Relatórios recentes de phishing e alterações de disponibilidade observadas
MonitorarMantenha-se informado, mantenha-se seguro
Monitore ameaças em tempo real ou conteste esta listagem caso acredite que se trate de um falso positivo