soft-side-946015[.]framer[.]app
“BT”
soft-side-946015.framer.app — İçerik kullanılamıyor. Kanıt özeti: VirusTotal 13/95 (ADMINUSLabs, alphaMountain.ai, BitDefender, CyRadar, ESET); CF Radar malicious; PhishDestroy score 89/100. Kayıt kuruluşu: CSC.
Özgün adli kaydı korumak için aşağıdaki ayrıntılı PhishDestroy AI analizi İngilizce bırakılmıştır.
The domain soft-side-946015.framer.app is flagged as a generic phishing site and is currently taken offline. Registration records show the domain was created on October 02, 2020 through CSC Corporate Domains, Inc., and it is served by four Amazon Route 53 name servers: ns-625.awsdns-14.net, ns-1371.awsdns-43.org, ns-2002.awsdns-58.co.uk, and ns-51.awsdns-. The hosting IP resolves to 52.223.52.2, which belongs to Amazon.com, Inc. (ASN 16509) and is geolocated in the United States. The site presents an SSL certificate issued by Let’s Encrypt with the identifier “E7”, confirming that TLS is active and HSTS is enforced.
HTTP probing returned a 404 status code, indicating the requested resource is not present, and the page title reported by the scanner is “BT”. Technical fingerprints reveal the use of Framer Sites, a React‑based front‑end, and support for HTTP/3, which are consistent with modern web‑app deployments but do not provide insight into malicious intent. Threat intelligence shows the domain appears on one security blocklist and has been explicitly blocked by PhishDestroy. VirusTotal analysis returned 13 positive detections out of 95 scanned engines, reinforcing the phishing classification.
No additional public intelligence such as OTX or Safe Browsing entries were observed. Given the available evidence, defenders should continue to block the domain at network perimeter and DNS layers, update any automated URL filtering lists with the observed indicator, and monitor for re‑appearance of the host on other blocklists. Because the site is offline, active exploitation cannot be confirmed, but the combination of registration details, blocklist presence, and multiple vendor detections justifies maintaining an elevated risk posture. Further investigation would be required to capture the page content before takedown, which could reveal the specific credential‑harvesting technique employed.
Ağ Güvenliği İstihbaratı
Tehdit Müdahale Pipeline
Genel Engelleme Listesi Durumu
Teknolojiler · 4 identified
Framer is a no-code web design platform for designing and publishing responsive websites.
www.framer.com %100 güvenReact is an open-source JavaScript library for building user interfaces or UI components.
reactjs.org %100 güvenHTTP Strict Transport Security (HSTS) informs browsers that the site should only be accessed using HTTPS.
www.rfc-editor.org %100 güvenHTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org %100 güvenVirusTotal Analizi
Arşivlenmiş Kanıtlar
Site Performans Analizi
Google PageSpeed Insights — mobile performance audit of soft-side-946015.framer.app · checked Mar 2, 2026
Kanıtlar ve Dış Raporlar
Bu Siteden Etkilendiniz mi?
Hesap kimlik bilgilerini, kişisel bilgileri veya ödeme bilgilerini girdiyseniz ya da bu alan adından bir dosya indirdiyseniz hemen harekete geçin. Aşağıda olayı bildirmenize ve kendinizi korumanıza yardımcı olacak kaynaklar bulunmaktadır.
Yerel Yetkililere Bildirin
resmi siber suç iletişim bilgileri veya şikayet taslağı oluştur → almak için ülkenizi seçin.
Herhangi Bir Alan Adını Kontrol Et
Saklanan engelleme listesi, WHOIS, DNS ve genel tarama kanıtlarını kullanarak tehdit analizi
Şimdi TaraOltalama Olayını Bildir
Şüpheli alan adlarını tehdit veritabanımıza bildirin — topluluğu koruyun
BildirCanlı Tehdit Akışı
Son kimlik avı raporları ve gözlemlenen kullanılabilirlik değişiklikleri
İzleGelişmelerden Haberdar Olun, Güvende Kalın
Canlı tehditleri izleyin veya bunun yanlış bir uyarı olduğunu düşünüyorsanız bu kayda itiraz edin