chilly-office-616371.framer.app
Category: Phishing
- Don't sign in or pay here. Close it. If you typed a password, change it where you normally use it.
- Already visited? Check your device. A free scan shows whether anything was installed.
- Stop the next one. Combo Cleaner's web protection blocks phishing and scam sites before they load.
Combo Cleaner is PCrisk's own anti-malware tool, owned by RCS LT. Free to scan; removing what it finds needs a licence (7-day free trial).
Quttera Web Malware Removal is a paid subscription service. Pricing, plans, and trial availability are set by Quttera. Quttera is operated by Quttera Ltd, an independent third-party company unrelated to RCS LT. PCrisk.com may earn a referral commission when users sign up through this link.
Description of chilly-office-616371.framer.app
This domain appears to be a page hosted on Framer, a website-building and hosting platform, rather than a standalone primary business domain. The page metadata is generic ("My Framer Site" / "Made with Framer"), which suggests it may be a quickly published landing page or prototype rather than an established official website with its own branded domain.
Based on the screenshot, the page presents a login form branded with "Uniwersytet Opolski" and "Microsoft 365," asking visitors for an email address and password. That combination suggests the page may be attempting to imitate an institutional or workplace sign-in experience. The underlying domain, however, is a random-looking Framer subdomain and does not appear to match the university or Microsoft branding shown on the page.
Safety Assessment for chilly-office-616371.framer.app
Scan results show mixed signals at the time of this scan. Two out of 91 security engines flagged the URL, including one phishing classification, while broader blacklist and threat-database checks did not report listings. The malware scan also marked the page and several hosted resources as suspicious, although those detections appear to be generic heuristic findings on Framer-hosted assets rather than named malware.
The stronger concern comes from the page content itself. The screenshot shows a credential-entry form using the branding of Uniwersytet Opolski and Microsoft 365, but it is hosted on an unrelated Framer subdomain with generic site metadata. That mismatch may indicate a look-alike login page intended to collect credentials, even though major blacklist databases were clean at the time of this scan.
Because the domain is several years old and hosted on a legitimate site-building platform, the infrastructure alone does not prove abuse. However, the combination of phishing-related engine detections, suspicious heuristics, and branding that does not match the hosting domain raises meaningful concern. Based on these findings, this website may pose potential risks to visitors.
Technical Description
The site uses a valid Let's Encrypt SSL certificate with expiry listed as 2026-12-31 and is served by a Framer web server hosted by Framer B.V on IP address 31.43.161.6 in Amsterdam, Netherlands. The domain uses AWS nameservers and the DNSSEC status is unsigned.
From a technical perspective, this appears to be a hosted subsite on framer.app rather than a dedicated institutional domain. That setup is common for temporary pages and prototypes, but in this case it also makes the branding mismatch more notable because the visible login page references a university and Microsoft 365 while the actual host remains an unrelated Framer subdomain.
Share your experience with this website. Was it safe? Did you encounter any issues?