whole-company-325511[.]framer[.]app
“My Framer Site”
whole-company-325511.framer.app — Conteúdo indisponível. Tipo de golpe: Credential Phishing. Resumo das evidências: VirusTotal 22 detections (engine total unavailable) (ADMINUSLabs, alphaMountain.ai, BitDefender, Cluster25, CRDF); URLQuery 3 alerts; CF Radar malicious; PhishDestroy score 100/100. Registrador: Framer.
A análise detalhada do PhishDestroy AI permanece em inglês para preservar o registro forense original.
PhishDestroy identifies whole-company-325511.framer.app as an active credential theft domain currently distributing malicious content designed to harvest user credentials. This domain is confirmed to be engaged in credential theft activities, posing an elevated risk to unsuspecting visitors. The infrastructure behind this domain is actively operational and has been observed distributing fraudulent login forms mimicking legitimate corporate platforms.
This domain was flagged by 22 of 95 VirusTotal security vendors, indicating significant malicious activity detection. The domain resolves to IP address 31.43.160.6 and utilizes a Let's Encrypt SSL certificate for deceptive legitimacy. The domain is associated with the Framer platform but has been weaponized to facilitate credential harvesting. It has been confirmed to appear on 2 active phishing blocklists, including OpenPhish and PhishingArmy, demonstrating cross-platform threat intelligence coverage. The current status is classified as active with a unique seed identifier of ab74a2.
Current status indicates this credential theft domain remains active and poses an ongoing threat to end users. PhishDestroy recommends immediate avoidance of this domain and any associated links or embedded content. Users who may have interacted with this domain should assume credential compromise and initiate password resets for all affected accounts. Additionally, organizations should consider blocking this domain at the network perimeter using the provided IP address and domain name indicators. Continuous monitoring for credential harvesting attempts and user awareness training are strongly advised to mitigate the risk of credential theft operations.
Inteligência de segurança de rede
Pipeline de resposta a ameaças
Status da lista de bloqueios pública
Tecnologias · 4 identified
Framer is a no-code web design platform for designing and publishing responsive websites.
www.framer.com 100% de confiançaReact is an open-source JavaScript library for building user interfaces or UI components.
reactjs.org 100% de confiançaHTTP Strict Transport Security (HSTS) informs browsers that the site should only be accessed using HTTPS.
www.rfc-editor.org 100% de confiançaHTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org 100% de confiançaAnálise do VirusTotal
Evidências e relatórios externos
PD-20260506-755247 Recipient: abuse@framer.com Você foi afetado por este site?
Se você inseriu credenciais de conta, informações pessoais ou de pagamento, ou baixou um arquivo deste domínio, tome medidas imediatas. Abaixo estão os recursos para ajudá-lo a relatar o incidente e se proteger.
Notifique as autoridades locais
Selecione seu país para obter contactos oficiais do cibercrime ou crie um rascunho de reclamação →.
Verificar qualquer domínio
Análise de ameaças usando lista de bloqueio armazenada, WHOIS, DNS e evidências de verificação pública
Digitalize agoraDenunciar phishing
Envie domínios suspeitos para nosso banco de dados de ameaças — proteja a comunidade
DenunciarFeed de ameaças em tempo real
Relatórios recentes de phishing e alterações de disponibilidade observadas
MonitorarMantenha-se informado, mantenha-se seguro
Monitore ameaças em tempo real ou conteste esta listagem caso acredite que se trate de um falso positivo