intellectual-travel-485898[.]framer[.]app
“My Framer Site”
intellectual-travel-485898.framer.app — Контент недоступен. Олицетворение бренда: Ar24; Тип мошенничества: Brand Impersonation. Сводка доказательств: VirusTotal 19/91 (alphaMountain.ai, BitDefender, Cluster25, CyRadar, ESET); URLQuery 4 alerts; URLScan malicious verdict; CF Radar malicious; PhishDestroy score 95/100. Регистратор: Framer.
Подробный анализ PhishDestroy AI ниже оставлен на английском, чтобы сохранить исходную криминалистическую запись.
The domain intellectual-travel-485898.framer.app is identified as a high-risk generic phishing threat, currently active and potentially impersonating legitimate services. The page title detected on this domain is 'My Framer Site', which suggests an attempt to mimic the Framer brand for malicious purposes. There is no identified drainer kit associated with this domain at this time.
Technical indicators for this domain include a VirusTotal detection score of 18 out of 95, indicating a significant level of concern raised by security vendors. The domain is registered through Framer and resolves to the IP address 31.43.161.6. Currently, there is no indication that this domain is listed on Google Safe Browsing (GSB), but it has been flagged by multiple security services. The detailed monitoring indicates an active status with potential for further proliferation.
As of now, the domain remains active with no immediate remedial actions taken by the registrar or involved parties. The presence of 18 security flags on VirusTotal highlights the urgency of mitigation measures. Users should refrain from interacting with this domain, and organizations are advised to implement network-level blocking to prevent access. Continuous monitoring is recommended to assess the evolution of this threat and its potential impact on users.
Данные сетевой безопасности
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| Cloudflare DNS | intellectual-travel-485898.framer.app |
malicious | Sinkholed |
| OpenDNS | intellectual-travel-485898.framer.app |
phishing | Phishing Block |
| DNS4EU | intellectual-travel-485898.framer.app |
malicious | Sinkholed |
| Quad9 DNS | intellectual-travel-485898.framer.app |
malicious | Sinkholed |
Процесс реагирования на угрозы
Статус в публичных блок-листах
Технологии · 4 identified
Framer is a no-code web design platform for designing and publishing responsive websites.
www.framer.com 100% уверенностиReact is an open-source JavaScript library for building user interfaces or UI components.
reactjs.org 100% уверенностиHTTP Strict Transport Security (HSTS) informs browsers that the site should only be accessed using HTTPS.
www.rfc-editor.org 100% уверенностиHTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org 100% уверенностиАнализ VirusTotal
Доказательства и внешние отчеты
PD-20260712-320A73 Recipient: abuse@framer.com Повлиял ли на вас этот сайт?
Если вы ввели учетные данные, личную или платежную информацию или загрузили файл с этого домена, примите немедленные меры. Ниже приведены ресурсы, которые помогут вам сообщить об инциденте и защитить себя.
Сообщите об этом в местные органы власти
Выберите свою страну, чтобы получить официальные контакты по киберпреступности или создать проект жалобы →.
Проверить любой домен
Анализ угроз с использованием сохраненного черного списка, WHOIS, DNS и общедоступных доказательств сканирования.
Сканировать сейчасСообщить о фишинге
Добавляйте подозрительные домены в нашу базу данных угроз — защищайте сообщество
СообщитьПоток оперативных данных об угрозах
Недавние сообщения о фишинге и наблюдаемые изменения доступности
ОтслеживатьБудьте в курсе событий, берегите себя
Отслеживайте актуальные угрозы или оспорьте эту запись, если считаете, что это ложное срабатывание