new-conference-643300[.]framer[.]app
“Site Not Found | Framer”
new-conference-643300.framer.app — İçerik kullanılamıyor. Kanıt özeti: VirusTotal 18/95 (ADMINUSLabs, alphaMountain.ai, BitDefender, Cluster25, CRDF); URLQuery 5 alerts; CF Radar malicious; PhishDestroy score 95/100. Kayıt kuruluşu: CSC.
Özgün adli kaydı korumak için aşağıdaki ayrıntılı PhishDestroy AI analizi İngilizce bırakılmıştır.
This domain, new-conference-643300.framer.app, has been identified as part of a credential theft phishing campaign targeting users of online collaboration and conferencing platforms. The site masqueraded as a legitimate service portal, likely leveraging social engineering tactics to harvest login credentials from unsuspecting victims. No specific drainer kit or cryptocurrency-related payloads were confirmed in this instance, though the infrastructure aligns with broader phishing operations observed in recent months. The page title, 'Site Not Found | Framer,' suggests the domain may have been part of a larger, ephemeral campaign designed to evade detection by rotating subdomains or hosting environments.
Technical indicators confirm the domain's malicious classification. The domain resolves to the IP address 31.43.160.6, hosted on infrastructure belonging to Amazon.com, Inc. (AS16509) in the Netherlands. It was registered through CSC Corporate Domains, Inc. on February 21, 2026, though the creation date may reflect an administrative placeholder rather than active deployment. At the time of analysis, the domain appeared on one security blocklist and was flagged by 18 out of 95 security vendors on VirusTotal. The SSL certificate, issued by Let's Encrypt (serial number E7), provided minimal assurance, as phishing domains frequently leverage free certificates to appear legitimate. No detections were reported in Google Safe Browsing at the time of this assessment, though this may reflect a lag in propagation rather than benign status.
The domain has since been taken offline, reducing immediate exposure risk. However, the infrastructure and registrar history suggest the operators may redeploy similar domains under different subdomains or parent domains. Users who interacted with the site are advised to rotate credentials for any accounts accessed during the exposure window, particularly those tied to professional or financial services. Organizations should monitor for additional subdomains under the framer.app parent domain and update blocklists to include the IP address 31.43.160.6. The elevated risk level persists due to the domain's prior use in credential theft, and defenders should treat any future iterations of this infrastructure as presumptively malicious.
Ağ Güvenliği İstihbaratı
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| Quad9 DNS | framercanvas.com |
malicious | Sinkholed |
| Cloudflare DNS | new-conference-643300.framer.app |
malicious | Sinkholed |
| OpenDNS | new-conference-643300.framer.app |
phishing | Phishing Block |
| DNS4EU | new-conference-643300.framer.app |
malicious | Sinkholed |
| Quad9 DNS | new-conference-643300.framer.app |
malicious | Sinkholed |
Tehdit Müdahale Pipeline
Genel Engelleme Listesi Durumu
Teknolojiler · 4 identified
Framer is a no-code web design platform for designing and publishing responsive websites.
www.framer.com %100 güvenReact is an open-source JavaScript library for building user interfaces or UI components.
reactjs.org %100 güvenHTTP Strict Transport Security (HSTS) informs browsers that the site should only be accessed using HTTPS.
www.rfc-editor.org %100 güvenHTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org %100 güvenVirusTotal Analizi
Site Performans Analizi
Google PageSpeed Insights — mobile performance audit of new-conference-643300.framer.app · checked Mar 2, 2026
Kanıtlar ve Dış Raporlar
Bu Siteden Etkilendiniz mi?
Hesap kimlik bilgilerini, kişisel bilgileri veya ödeme bilgilerini girdiyseniz ya da bu alan adından bir dosya indirdiyseniz hemen harekete geçin. Aşağıda olayı bildirmenize ve kendinizi korumanıza yardımcı olacak kaynaklar bulunmaktadır.
Yerel Yetkililere Bildirin
resmi siber suç iletişim bilgileri veya şikayet taslağı oluştur → almak için ülkenizi seçin.
Herhangi Bir Alan Adını Kontrol Et
Saklanan engelleme listesi, WHOIS, DNS ve genel tarama kanıtlarını kullanarak tehdit analizi
Şimdi TaraOltalama Olayını Bildir
Şüpheli alan adlarını tehdit veritabanımıza bildirin — topluluğu koruyun
BildirCanlı Tehdit Akışı
Son kimlik avı raporları ve gözlemlenen kullanılabilirlik değişiklikleri
İzleGelişmelerden Haberdar Olun, Güvende Kalın
Canlı tehditleri izleyin veya bunun yanlış bir uyarı olduğunu düşünüyorsanız bu kayda itiraz edin