Analysis indicates that the domain favorite-guava-958784.framer.app is actively used for phishing. The domain is listed on two public blocklists and is blocked by PhishDestroy and OpenPhish, confirming its presence in recognized threat feeds. VirusTotal has recorded detections from 18 of 91 scanned security vendors, reinforcing the malicious classification. The domain resolves to the IP address 31.43.160.6; no additional hosting details are provided.
Registration information shows the domain was created through the registrar Framer B.V., a service commonly used for rapid deployment of web content. Nameserver data is unavailable (NS_NOT_FOUND), limiting insight into DNS infrastructure. The threat is categorized as generic phishing and remains active as of the report date, July 30, 2026, with a high risk rating. No SSL certificate information, HTTP response codes, page title, or brand targeting details are currently available, leaving the exact content and lure mechanisms unverified.
Defenders should continue to block the domain at network perimeter and proxy layers, add the IP address to deny lists, and monitor for any related sub‑domains that may resolve to the same host. Incident response teams should treat any credential or data submission attempts originating from this domain as compromised and advise users to avoid interaction. Ongoing vigilance is recommended, including periodic re‑scanning of the domain on VirusTotal and other sandbox services to capture any changes in behavior.