VirusTotal
7 / 95
“Sign in with your Telstra ID”
telstrawebpersonalservice.framer.website — Контент недоступний (HTTP 404). Уособлення бренду: Telstra; Тип шахрайства: Credential Phishing. Зведення доказів: VirusTotal 7/95 (alphaMountain.ai, Forcepoint ThreatSeeker, Fortinet, Kaspersky, Phishing Database); URLQuery 100 det.; URLScan malicious verdict; Spamhaus DBL_PHISH; CF Radar malicious; PhishDestroy score 100/100. Реєстратор: CSC.
Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.
7 / 95
100 det.
provider verdict: malicious
Повідомитиmalicious
ПовідомитиDBL_PHISH
no community references
Повідомитизбережений звіт
Повідомити Checked; no threat flag recorded
ПовідомитиThis report details a domain, telstrawebpersonalservice.framer.website, which hosted a credential phishing page impersonating the brand Telstra. The page title, "Sign in with your Telstra ID," indicates the site was designed to deceive users into entering their Telstra account credentials. The primary threat posed by this site is the theft of login credentials, which could lead to unauthorized account access.
Technical analysis reveals that the domain was flagged by 7 out of 95 VirusTotal vendors, including alphaMountain.ai, Forcepoint ThreatSeeker, Fortinet, Kaspersky, and Phishing Database. It is listed on 2 blocklists. The domain is registered with CSC Corporate Domains, Inc., and was created on 2021-11-19. It resolves to IP address 35.71.142.77, located in the United States and hosted on AS16509 (Amazon.com, Inc.). The site uses a Let's Encrypt SSL certificate (E7) and has nameservers ns-1243.awsdns-27.org, ns-1818.awsdns-35.co.uk, ns-336.awsdns-42.com, and ns-792.awsdns.
The domain is currently offline, reducing immediate risk of credential theft. However, given its history of phishing detections and brand impersonation, the risk level is assessed as high for any users who may have previously visited the site and entered credentials. Users should change their Telstra account passwords if they interacted with this site.
Збережені дані спостережень за взаємодією веб-сканера та браузера для цього хоста, а також перевірка відбитків у режимі реального часу для систем розподілу трафіку типу «Кейтаро».
Framer/26fa766Примітка щодо сканера: hosting_placeholder: raw=placeholder; http=404; via=https_proxy; server=Framer/26fa766
ns-1243.awsdns-27.orgns-1818.awsdns-35.co.ukns-336.awsdns-42.comns-792.awsdns-35.netLocation describes the IP network.
b3445573cc07ede57a843d22babf8e3b977a95a08dd21a6706de7226e732d6ceSaved certificate metadata. Certificate dates without a timezone are shown as stored. Transport encryption does not establish that the site is trustworthy.
16 recorded events. These records describe collected evidence, outgoing notifications and publication; they do not confirm a complete investigation or a takedown.
We scan suspicious URLs, inspect public results and send evidence through the appropriate abuse-reporting channels. The dated events above show what is recorded for this domain. The directory below explains the wider workflow.
Capture the rendered page, requests and visible infrastructure.
Compare the available engine results and retain the analysis timestamp.
Check whether Google currently lists the URL as unsafe.
Inspect a public scan and its recorded network and classification data.
Look for indicator references and related community intelligence.
Compare archived captures and preserve historical context.
Look for matching indicators and associated threat records.
Inspect certificate records and related hostnames.
Compare security resolver responses and record observed blocking.
Inspect the public DNS, TLS, HTTP and technology surface.
Security services used for scanning, reputation checks and reporting are listed below. A service being listed is not evidence that it received, accepted or acted on this particular domain. Recorded submissions appear in the notification history above.
Повідомив 1 учасник спільноти; уперше помічено 24.10.2025
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Template-based draft · optional AI wording assistance requires separate consent
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразДодавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиОстанні звіти про фішинг і помічені зміни доступності
ВідстежуватиСлідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога