VirusTotal
5 / 93
“Site Not Found | Framer”
start-dafilamba-web.framer.website — Контент недоступний (HTTP 404). Тип шахрайства: Generic Phishing. Зведення доказів: VirusTotal 5/93 (ADMINUSLabs, ChainPatrol, alphaMountain.ai, CyRadar, Google Safebrowsing); Google Safe Browsing flagged; Spamhaus DBL_PHISH; PhishDestroy score 90/100. Реєстратор: CSC.
Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.
5 / 93
Threat flag recorded
ПовідомитиDBL_PHISH
no community references
Повідомитизбережений звіт
Повідомити Аналіз завершено
ПовідомитиThe domain start-dafilamba-web.framer.website was registered on February 21, 2026 through CSC Corporate Domains, Inc. and resolves to the Amazon‑owned IP address 35.71.142.77, which is advertised as belonging to AS16509 Amazon.com, Inc. The authoritative name servers listed for the zone are ns-1243.awsdns-27.org, ns-1818.awsdns-35.co.uk, ns-336.awsdns-42.com, among others. An HTTPS service is present, presenting an SSL certificate identified only as "E7"; no further certificate details are available. When accessed, the site returns an HTTP 404 status and the page title "Site Not Found | Framer," indicating that the content is currently unavailable.
Google Safe Browsing marks the domain for social engineering, and the independent blocklist PhishDestroy has recorded it as malicious, classifying the threat as generic phishing. VirusTotal analysis shows that five of ninety‑three scanners flagged the domain, and it appears on a single public blocklist. The combination of registrar information, hosting on a cloud provider, a valid TLS endpoint, and multiple independent detections suggests an active malicious infrastructure that was taken offline at the time of reporting.
Defenders should continue to block the domain at perimeter and DNS layers, monitor for any re‑activation of the same host or related subdomains, and consider adding the associated IP address to reputation‑based deny lists. Because the site currently returns a 404 page, content‑level inspection is not possible, and the exact phishing payload or targeted brand remains unknown. Ongoing vigilance is required to detect any future resurrection of the domain or the reuse of its hosting resources for new campaigns.
Збережені дані спостережень за взаємодією веб-сканера та браузера для цього хоста, а також перевірка відбитків у режимі реального часу для систем розподілу трафіку типу «Кейтаро».
Framer/26fa766Примітка щодо сканера: hosting_placeholder: raw=placeholder; http=404; via=https_proxy; server=Framer/26fa766
ns-792.awsdns-35.netLocation describes the IP network.
Saved certificate metadata. Certificate dates without a timezone are shown as stored. Transport encryption does not establish that the site is trustworthy.
11 recorded events. These records describe collected evidence, outgoing notifications and publication; they do not confirm a complete investigation or a takedown.
We scan suspicious URLs, inspect public results and send evidence through the appropriate abuse-reporting channels. The dated events above show what is recorded for this domain. The directory below explains the wider workflow.
Capture the rendered page, requests and visible infrastructure.
Compare the available engine results and retain the analysis timestamp.
Check whether Google currently lists the URL as unsafe.
Inspect a public scan and its recorded network and classification data.
Look for indicator references and related community intelligence.
Compare archived captures and preserve historical context.
Look for matching indicators and associated threat records.
Inspect certificate records and related hostnames.
Compare security resolver responses and record observed blocking.
Inspect the public DNS, TLS, HTTP and technology surface.
Security services used for scanning, reputation checks and reporting are listed below. A service being listed is not evidence that it received, accepted or acted on this particular domain. Recorded submissions appear in the notification history above.
Повідомив 1 учасник спільноти; уперше помічено 05.12.2025
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Template-based draft · optional AI wording assistance requires separate consent
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразДодавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиОстанні звіти про фішинг і помічені зміни доступності
ВідстежуватиСлідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога