glowing-gibbon-300775.framer.app
Category: Phishing
To use full-featured product, you have to purchase a license for Combo Cleaner. Limited seven days free trial available. Combo Cleaner is owned and operated by RCS LT, the parent company of PCRisk.com.
Quttera Web Malware Removal is a paid subscription service. Pricing, plans, and trial availability are set by Quttera. Quttera is operated by Quttera Ltd, an independent third-party company unrelated to RCS LT. PCrisk.com may earn a referral commission when users sign up through this link.
Description of glowing-gibbon-300775.framer.app
This domain appears to be a page hosted on Framer, a website-building and hosting platform, rather than a standalone branded domain. The page metadata is generic ("My Framer Site" / "Made with Framer"), which suggests it may be a quickly published landing page or prototype rather than an established official website with its own identity.
Based on the screenshot, the page presents itself as a TalkTalk sign-in portal and asks visitors to enter an email address and password. The layout imitates a telecommunications account login experience, including TalkTalk branding and references to mail access. There is no clear indication on the page that it is officially operated by TalkTalk, and the use of a Framer subdomain instead of a brand-owned domain is notable.
The site appears to be delivered through Framer infrastructure and references Framer-hosted assets from framerusercontent.com. In practical terms, this means the content may have been created by a third party using a legitimate hosting platform, which can be used for benign projects but may also be used to publish deceptive login pages.
Safety Assessment for glowing-gibbon-300775.framer.app
Multiple independent security signals indicate elevated risk at the time of this scan. The domain was flagged by 18 out of 91 security engines, with many of those detections classifying it as phishing or fraud-related. In addition, one phishing-focused threat database listed the URL, and the screenshot shows a credential-entry page that appears to imitate TalkTalk while being hosted on a Framer subdomain rather than an official TalkTalk web address.
The automated malware scan also marked the page and several linked resources as suspicious, although those generic heuristic findings are lower-confidence on their own. More importantly, the visible page behavior and branding pattern are consistent with a look-alike login page intended to collect account credentials. The domain's IP address is also listed on one mail-reputation blocklist, which is a weaker signal than phishing detections but still adds some caution.
Because the page appears to mimic a telecommunications login and because there is broad multi-engine phishing consensus, the overall risk profile is high based on available data. Based on these findings, this website may pose potential risks to visitors.
Technical Description
The site uses a valid Let's Encrypt SSL certificate with an expiry date in 2026, which means traffic to the page appears to be encrypted in transit. It is hosted on Framer infrastructure (reported web server: Framer/5d364ee) at IP address 31.43.160.6 in Amsterdam, Netherlands, and loads most of its assets from framerusercontent.com. The domain itself is a subdomain under framer.app rather than a dedicated brand-owned domain.
DNSSEC appears to be unsigned, and the reported protocol details are incomplete. While the TLS certificate is valid, that should not be taken as proof of legitimacy; phishing pages commonly use HTTPS as well. The main technical concern here is not the server setup itself, but the apparent mismatch between the displayed TalkTalk branding and the non-official hosting/domain context.
Share your experience with this website. Was it safe? Did you encounter any issues?