thistle-growth-813561[.]framer[.]app
“Xfinity Sign In”
thistle-growth-813561.framer.app — Conteúdo indisponível. Representação da marca: Xfinity; Tipo de golpe: Credential Phishing. Resumo das evidências: VirusTotal 22/91 (ADMINUSLabs, alphaMountain.ai, BitDefender, Chong Lua Dao, Cluster25); URLQuery 1 alert; URLScan malicious verdict; Google Safe Browsing flagged; CF Radar malicious; PhishDestroy score 100/100. Registrador: Framer.
A análise detalhada do PhishDestroy AI permanece em inglês para preservar o registro forense original.
PhishDestroy identifies thistle-growth-813561.framer.app as an active credential theft page posing as Xfinity’s login portal. This site lures visitors into surrendering sensitive account credentials by mimicking the legitimate Xfinity sign-in interface. Once harvested, these stolen credentials can be weaponized for unauthorized account access, financial fraud, or identity theft. This domain was flagged by 19 out of 95 VirusTotal security vendors and blacklisted by Google Safe Browsing for SOCIAL_ENGINEERING tactics. It resolves to IP 31.43.161.6 and uses a Let’s Encrypt SSL certificate to appear legitimate. The page title “Xfinity Sign In” is deliberately spoofed to deceive users into lowering their guard. This site likely surfaced recently, exploiting the trust associated with Xfinity to bypass security awareness. If you visited this page, immediately change your Xfinity password using a known-good device and enable multi-factor authentication. Scan your system for malware using an up-to-date antivirus tool and review recent account activity for unauthorized logins. Report the domain to your security team and avoid interacting with similar links in the future.
Inteligência de segurança de rede
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| OpenDNS | thistle-growth-813561.framer.app |
phishing | Phishing Block |
Pipeline de resposta a ameaças
Status da lista de bloqueios pública
Tecnologias · 4 identified
Framer is a no-code web design platform for designing and publishing responsive websites.
www.framer.com 100% de confiançaReact is an open-source JavaScript library for building user interfaces or UI components.
reactjs.org 100% de confiançaHTTP Strict Transport Security (HSTS) informs browsers that the site should only be accessed using HTTPS.
www.rfc-editor.org 100% de confiançaHTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org 100% de confiançaAnálise do VirusTotal
Análise de desempenho do site
Google PageSpeed Insights — mobile performance audit of thistle-growth-813561.framer.app · checked Apr 28, 2026
Evidências e relatórios externos
PD-20260428-7B0108 Recipient: abuse@framer.com Você foi afetado por este site?
Se você inseriu credenciais de conta, informações pessoais ou de pagamento, ou baixou um arquivo deste domínio, tome medidas imediatas. Abaixo estão os recursos para ajudá-lo a relatar o incidente e se proteger.
Notifique as autoridades locais
Selecione seu país para obter contactos oficiais do cibercrime ou crie um rascunho de reclamação →.
Verificar qualquer domínio
Análise de ameaças usando lista de bloqueio armazenada, WHOIS, DNS e evidências de verificação pública
Digitalize agoraDenunciar phishing
Envie domínios suspeitos para nosso banco de dados de ameaças — proteja a comunidade
DenunciarFeed de ameaças em tempo real
Relatórios recentes de phishing e alterações de disponibilidade observadas
MonitorarMantenha-se informado, mantenha-se seguro
Monitore ameaças em tempo real ou conteste esta listagem caso acredite que se trate de um falso positivo