Analysis of the domain minimum-personalization-528224.framer.app indicates an active high-risk phishing campaign as of July 31, 2026. The domain is registered through Framer B.V. and currently resolves to the IP address 31.43.160.6, though nameserver records appear missing or misconfigured. Detection data from VirusTotal shows that 18 of 91 security vendors have flagged this domain as malicious, suggesting a moderate but growing level of consensus among threat intelligence providers. The domain is also blocked by PhishDestroy and appears on at least one additional security blocklist, reinforcing its classification as a confirmed phishing threat.
Infrastructure analysis reveals that the domain is hosted on Framer’s platform, which is a legitimate service commonly abused for phishing due to its ease of deployment and free tier availability. The absence of nameserver records may indicate an attempt to evade detection or a misconfiguration during setup. No brand-specific indicators or page content details are currently available, so the exact target or phishing kit in use remains unconfirmed. Defenders should note that the domain remains active and continues to resolve, posing an ongoing risk to users.
Organizations are advised to implement immediate blocking of the domain and its associated IP address (31.43.160.6) at the network perimeter. Security teams should monitor for connections to this domain in logs and endpoint telemetry, as it may indicate compromised credentials or attempted phishing activity. Given the domain’s registration under Framer B.V., defenders may also consider reviewing other recently registered Framer-hosted domains for similar patterns of abuse. Further investigation into the phishing kit or campaign infrastructure is recommended to determine the scope of the threat and potential victim profiles.