VirusTotal
5 / 91
“Site Not Found | Framer”
webcoibase-net.framer.website — Conteúdo indisponível (HTTP 404). Tipo de golpe: Brand Impersonation. Resumo das evidências: VirusTotal 5/91 (ChainPatrol, alphaMountain.ai, Chong Lua Dao, Forcepoint ThreatSeeker, Webroot); PhishDestroy score 65/100. Registrador: CSC.
A análise detalhada do PhishDestroy AI permanece em inglês para preservar o registro forense original.
Analysis of the domain webcoibase-net.framer.website shows a short-lived phishing infrastructure that was taken offline prior to the report date of July 23, 2026. The domain was registered on February 21, 2026 through CSC Corporate Domains, Inc. and resolves to the Amazon Web Services address 35.71.142.77, belonging to ASN 16509 (Amazon.com, Inc.) in the United States. DNS is served by four AWS Route 53 nameservers (ns-1243.awsdns-27.org, ns-1818.awsdns-35.co.uk, ns-336.awsdns-42.com, and one truncated entry), indicating typical cloud‑hosted deployment. The site presented a valid TLS certificate issued by Let’s Encrypt (certificate identifier E7), confirming HTTPS support.
HTTP probing returns a 404 status with the page title "Site Not Found | Framer", suggesting the original content has been removed but the domain remains under observation. Technical fingerprints reveal the use of Framer Sites, React, HTTP/3, and HSTS, all consistent with a modern front‑end stack often leveraged by phishing actors to mimic legitimate branding. VirusTotal reports six of ninety‑three scanning engines flagging the domain, and the domain is listed on a single security blocklist. Independent threat‑intel services such as PhishDestroy have already blocked the domain, categorising the campaign as brand impersonation.
While the current HTTP response indicates no active payload, the historical presence of a phishing page cannot be ruled out; the domain may be repurposed or re‑activated. Defenders should continue to enforce DNS and IP‑based blocking for 35.71.142.77, monitor the certificate for renewal or changes, and add the domain to internal watchlists. Continuous observation of the registrar and name‑server configuration is advised, as any alteration could signal re‑deployment of malicious content. Until further content is observed, the risk rating remains elevated due to the confirmed phishing classification and the recent creation date.
Observações armazenadas comparando o rastreador com o navegador para este host, além de uma verificação em tempo real da assinatura digital para sistemas de distribuição de tráfego do tipo Keitaro.
Framer/26fa766Nota do digitalizador: hosting_placeholder: raw=placeholder; http=404; via=https_proxy; server=Framer/26fa766
ns-792.awsdns-35.netLocation describes the IP network.
b3445573cc07ede57a843d22babf8e3b977a95a08dd21a6706de7226e732d6ceSaved certificate metadata. Certificate dates without a timezone are shown as stored. Transport encryption does not establish that the site is trustworthy.
Google PageSpeed Insights — mobile performance audit of webcoibase-net.framer.website · checked Mar 2, 2026
13 recorded events. These records describe collected evidence, outgoing notifications and publication; they do not confirm a complete investigation or a takedown.
We scan suspicious URLs, inspect public results and send evidence through the appropriate abuse-reporting channels. The dated events above show what is recorded for this domain. The directory below explains the wider workflow.
Capture the rendered page, requests and visible infrastructure.
Compare the available engine results and retain the analysis timestamp.
Check whether Google currently lists the URL as unsafe.
Inspect a public scan and its recorded network and classification data.
Look for indicator references and related community intelligence.
Compare archived captures and preserve historical context.
Look for matching indicators and associated threat records.
Inspect certificate records and related hostnames.
Compare security resolver responses and record observed blocking.
Inspect the public DNS, TLS, HTTP and technology surface.
Security services used for scanning, reputation checks and reporting are listed below. A service being listed is not evidence that it received, accepted or acted on this particular domain. Recorded submissions appear in the notification history above.
Se você inseriu credenciais de conta, informações pessoais ou de pagamento, ou baixou um arquivo deste domínio, tome medidas imediatas. Abaixo estão os recursos para ajudá-lo a relatar o incidente e se proteger.
Selecione seu país para obter contactos oficiais do cibercrime ou crie um rascunho de reclamação →.
Template-based draft · optional AI wording assistance requires separate consent
Análise de ameaças usando lista de bloqueio armazenada, WHOIS, DNS e evidências de verificação pública
Digitalize agoraEnvie domínios suspeitos para nosso banco de dados de ameaças — proteja a comunidade
DenunciarRelatórios recentes de phishing e alterações de disponibilidade observadas
MonitorarMonitore ameaças em tempo real ou conteste esta listagem caso acredite que se trate de um falso positivo