The domain cyan-ice-675590.framer.app is currently active and has been identified as a high‑risk phishing infrastructure. Google Safe Browsing classifies the site under the social engineering category, indicating that the URL is being used to lure users into divulging credentials or personal data. VirusTotal analysis shows that 7 out of 91 scanned security engines flag the domain as malicious, providing independent confirmation of the threat. The registration record lists Framer B.V. as the registrar, a detail that aligns with the .framer.app sub‑domain namespace. Network resolution points to the IPv4 address 31.43.161.6; no alternate A or AAAA records were observed, suggesting a single‑host deployment. The domain appears on one public blocklist and is explicitly blocked by the PhishDestroy service, demonstrating that at least one security‑focused organization has taken mitigation action. Nameserver information could not be retrieved, which may reflect a misconfiguration or deliberate obscuration of DNS infrastructure.
No public page title, SSL certificate details, or HTTP response codes have been disclosed, leaving the exact content and delivery mechanisms of the phishing page unknown. Consequently, analysts cannot confirm the specific brand or service being impersonated, nor can they attribute a particular phishing kit to the site. The absence of these artefacts limits the ability to map the full attack chain but does not diminish the observed indicators of compromise.
Defenders should prioritize immediate containment of traffic to cyan-ice-675590.framer.app by adding the domain to DNS‑based blocklists, proxy filters, and endpoint allow‑list exclusions. Continuous monitoring of DNS queries for the associated IP address (31.43.161.6) is advised, as any shift in hosting patterns could signal campaign expansion.