happier-mercury-665352[.]framer[.]app
“Saisie de vos identifiant Orange”
happier-mercury-665352.framer.app — Контент недоступний. Тип шахрайства: Generic Phishing. Зведення доказів: VirusTotal 19/94 (BitDefender, Cluster25, CRDF, CyRadar, ESET); URLQuery 3 alerts; PhishDestroy score 100/100. Реєстратор: Framer.
Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.
This domain, happier-mercury-665352.framer.app, operates as a credential theft platform designed to harvest user login credentials through deceptive authentication prompts. Analysis indicates the site mimics legitimate login portals, tricking visitors into entering sensitive information such as usernames, passwords, and potentially multi-factor authentication codes. The stolen credentials are likely exfiltrated to attacker-controlled infrastructure for unauthorized account access, financial fraud, or further phishing distribution. No evidence of crypto wallet drainers or malware payloads was observed, distinguishing this as a targeted credential harvesting operation rather than a broader financial theft campaign. Technical indicators confirm the malicious nature of this domain. The site was registered on April 9, 2026, through Framer, a legitimate platform often abused for hosting phishing pages due to its free tier and SSL certificate provisioning. It resolves to the IP address 31.43.161.6, located in the Netherlands under Framer B.V.'s infrastructure. Detection metrics further validate the threat: 19 out of 95 security vendors on VirusTotal flag the domain as malicious, with classifications ranging from phishing to credential theft. The domain appears on one security blocklist and was proactively taken offline, though residual risks may persist from cached or mirrored versions. The SSL certificate, issued by Let's Encrypt, provides no inherent trust, as it is automatically generated for all Framer-hosted domains. Users who visited happier-mercury-665352.framer.app should assume their credentials were compromised. Immediately change passwords for any accounts entered on the site, prioritizing email, financial, and work-related services. Enable multi-factor authentication using app-based or hardware tokens, avoiding SMS-based methods if possible. Monitor accounts for unauthorized activity, such as logins from unfamiliar locations or devices, and report suspicious transactions to the relevant service providers. If personal or corporate data was exposed, consider placing a fraud alert with credit bureaus or implementing additional monitoring. Organizations should review logs for connections to the IP 31.43.161.6 and the domain itself, as these may indicate broader compromise. Avoid interacting with any communications claiming to be from the site, as follow-up phishing attempts are common.
Розвіддані з мережевої безпеки
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| Cloudflare DNS | happier-mercury-665352.framer.app |
malicious | Sinkholed |
| OpenDNS | happier-mercury-665352.framer.app |
phishing | Phishing Block |
| CIRA Canadian Shield DNS | happier-mercury-665352.framer.app |
malicious | Sinkholed |
Процес реагування на загрози Pipeline
Статус у публічних блоклистах
Аналіз VirusTotal
Аналіз продуктивності сайту
Google PageSpeed Insights — mobile performance audit of happier-mercury-665352.framer.app · checked Apr 9, 2026
Докази та зовнішні звіти
PD-20260409-54A393 Recipient: abuse@framer.com Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога