Analysis of small-desktop-233616.framer.app indicates that the domain is actively being used for a phishing campaign. The domain resolves to the IPv4 address 31.43.161.6 and is registered through Framer B.V., a registrar associated with the framer.app sub‑domain space. Reputation services have flagged the site; PhishDestroy has listed it as blocked, and it appears on one additional security blocklist.
VirusTotal scans show that 18 of 91 security vendors have identified the domain as malicious, reinforcing the high‑risk assessment. The domain’s nameserver information could not be retrieved (NS_NOT_FOUND), which limits further DNS‑level attribution. Current status remains active, suggesting the infrastructure is still operational.
Defenders should block network traffic to both the domain and its resolved IP, add the host to local and cloud‑based URL filtering policies, and monitor for any related indicators of compromise. Continuous re‑scanning on VirusTotal and inclusion in threat‑intel feeds are recommended to capture any changes in vendor detections. Given the confirmed phishing activity and the presence on multiple blocklists, the domain should be treated as a high‑severity threat.