Analysis of coenbaze.framer.ai confirms an active high-risk phishing domain registered through Framer B.V. and resolving to 31.43.160.6 as of August 1, 2026. The domain is currently flagged by three independent security blocklists and has been preemptively blocked by PhishDestroy, MetaMask, and SEAL, indicating broad industry recognition of malicious intent. Infrastructure review reveals the domain lacks assigned nameservers (NS_NOT_FOUND), a common indicator of disposable or rapidly deployed phishing infrastructure.
No SSL certificate data or HTTP response details are available in current telemetry, preventing assessment of encryption status or live page content. The absence of a page title or brand target in available intelligence suggests the exact phishing lure is not yet classified, though the domain structure and hosting pattern align with credential harvesting campaigns.
Defenders should treat this domain as hostile and implement immediate blocking at DNS, proxy, and endpoint layers. No legitimate traffic is expected from this infrastructure, and continued monitoring is advised to identify any shifts in hosting or naming patterns.