logical-words-764346.framer.app
Category: Phishing
To use full-featured product, you have to purchase a license for Combo Cleaner. Limited seven days free trial available. Combo Cleaner is owned and operated by RCS LT, the parent company of PCRisk.com.
Quttera Web Malware Removal is a paid subscription service. Pricing, plans, and trial availability are set by Quttera. Quttera is operated by Quttera Ltd, an independent third-party company unrelated to RCS LT. PCrisk.com may earn a referral commission when users sign up through this link.
Description of logical-words-764346.framer.app
This domain appears to be a page hosted on Framer, a website-building and hosting platform, rather than a standalone corporate domain. The page title and visible content are in French and present what looks like an "Espace Client" login form asking for an Orange account identifier and password. Based on the screenshot, the page is designed to resemble a customer sign-in portal for the Orange telecommunications brand.
The domain name itself, logical-words-764346.framer.app, does not appear to match Orange's official branding and instead follows an autogenerated subdomain pattern commonly used for hosted landing pages. The metadata also indicates it was made with Framer, suggesting the page may be a quickly deployed hosted site rather than an official telecom customer portal.
Based on the available categories and page content, this website appears to be associated with credential collection activity targeting telecom users, or at minimum a page imitating a telecom login experience.
Safety Assessment for logical-words-764346.framer.app
Multiple security signals indicate elevated risk at the time of this scan. The domain was flagged by 20 out of 91 security engines, and several web-classification sources categorized it as phishing or fraud-related. In addition, one threat database listed the URL, and the screenshot shows a login page visually presenting itself as an Orange customer account portal while using an unrelated Framer subdomain. That mismatch may indicate brand impersonation intended to collect account credentials.
The malware scan also marked the page and several linked resources as suspicious, although those generic heuristic findings are lower-confidence on their own. More importantly, the visible content pattern, the hosted subdomain structure, the phishing-oriented classifications, and the multi-engine consensus together provide stronger evidence of abuse. The domain's IP address is also listed on one mail-reputation blocklist, which is a weaker signal by itself but adds a small amount of caution.
Based on these findings, this website may pose potential risks to visitors, particularly if asked to enter login credentials or personal information.
Technical Description
The site is hosted by Framer B.V on IP address 31.43.161.6 in Amsterdam, Netherlands, and serves content through a valid Let's Encrypt SSL certificate that was valid at the time of scanning. The web server identified itself as Framer/57d0062. DNSSEC appears to be unsigned, which is not uncommon but does mean DNS responses do not benefit from that additional integrity layer.
From a technical perspective, the page appears lightweight and largely composed of Framer-hosted assets from framerusercontent.com. While the TLS certificate is valid, HTTPS alone does not verify the legitimacy of the page's purpose. The main concern here is not transport security but the apparent use of a hosted subdomain to imitate a telecom login page.
Share your experience with this website. Was it safe? Did you encounter any issues?