started-desktop[.]framer[.]media
“Site Not Found | Framer”
started-desktop.framer.media — Conteúdo indisponível. Resumo das evidências: VirusTotal 11/93 (ADMINUSLabs, alphaMountain.ai, BitDefender, CRDF, CyRadar); PhishDestroy score 83/100. Registrador: CSC.
A análise detalhada do PhishDestroy AI permanece em inglês para preservar o registro forense original.
The domain started-desktop.framer.media was created on November 19, 2021 and is currently listed on at least one public security blocklist. Automated analysis shows the domain resolves to the public IP address 52.223.52.2, which is owned by Amazon.com, Inc. (AS16509) and geolocated to the United States. The authoritative name servers are ns-1267.awsdns-30.org, ns-1854.awsdns-39.co.uk, ns-535.awsdns-02.net and ns-97.awsdns- (truncated in the source data), indicating the domain is hosted on AWS DNS infrastructure. Registration is handled by CSC Corporate Domains, Inc., a registrar commonly used for bulk domain registrations.
The TLS certificate is issued by Let’s Encrypt (E7), and the site advertises modern transport features such as HTTP/3 and HSTS, confirming that the server is configured for secure communications despite the content being unavailable. A request to the HTTP endpoint returns a 404 status and the page title "Site Not Found | Framer", suggesting the original content has been removed or taken offline, which aligns with the reported offline status. VirusTotal scans have identified the domain as malicious in 11 of 93 security vendor engines, and the domain is explicitly blocked by PhishDestroy, reinforcing the classification as a phishing resource.
While the current HTTP response indicates no active payload, the historical presence of a Framer-based site and the combination of blocklist listings, vendor detections, and the AWS hosting context provide sufficient evidence for defenders to treat the domain as a confirmed phishing indicator. Defensive actions should include adding the domain and its resolved IP address to outbound and inbound deny lists, monitoring for any future DNS resolution changes, and correlating internal logs for any attempts to contact the domain or associated IP. Continuous re‑evaluation is advised in case the site is re‑activated, but the existing evidence warrants immediate blocking and alerting for any related activity.
Pipeline de resposta a ameaças
Status da lista de bloqueios pública
Tecnologias · 4 identified
JavaScript library for building user interfaces with component-based architecture.
HTTP Strict Transport Security — forces browsers to use HTTPS connections only.
Third major version of HTTP protocol, built on QUIC for faster, more reliable connections.
Análise do VirusTotal
Evidências arquivadas
Evidências e relatórios externos
Você foi afetado por este site?
Se você inseriu credenciais de conta, informações pessoais ou de pagamento, ou baixou um arquivo deste domínio, tome medidas imediatas. Abaixo estão os recursos para ajudá-lo a relatar o incidente e se proteger.
Notifique as autoridades locais
Selecione seu país para obter contactos oficiais do cibercrime ou crie um rascunho de reclamação →.
Verificar qualquer domínio
Análise de ameaças usando lista de bloqueio armazenada, WHOIS, DNS e evidências de verificação pública
Digitalize agoraDenunciar phishing
Envie domínios suspeitos para nosso banco de dados de ameaças — proteja a comunidade
DenunciarFeed de ameaças em tempo real
Relatórios recentes de phishing e alterações de disponibilidade observadas
MonitorarMantenha-se informado, mantenha-se seguro
Monitore ameaças em tempo real ou conteste esta listagem caso acredite que se trate de um falso positivo