The domain left-pitch-487249.framer.app is currently active and resolves to the IPv4 address 31.43.160.6. Registration information shows it was created through the Framer B.V. platform, a service that provides hosting for user‑generated web projects. The domain has been listed on two reputable phishing blocklists, PhishDestroy and OpenPhish, indicating that it has been observed distributing malicious content. VirusTotal scans have returned 19 positive detections out of 91 submitted engines, reinforcing the suspicion of malicious intent.
No authoritative name server information could be retrieved (NS_NOT_FOUND), and public DNS queries do not reveal additional sub‑domains or CNAME records. Existing intelligence does not include a page title, SSL certificate details, HTTP response codes, or Safe Browsing verdicts, so the exact nature of the hosted page remains unknown. The lack of visible TLS information suggests that the site may be operating without HTTPS, which is common for phishing pages hosted on free‑form platforms.
Defenders should continue to block the domain at perimeter filters, add it to local blocklists, and monitor outbound traffic for connections to 31.43.160.6. Incident response teams encountering email or credential‑theft attempts that reference this domain should treat any user interaction as compromised and advise immediate credential reset. Ongoing surveillance of the IP address and periodic rescans with VirusTotal or similar engines are recommended to capture any changes in the detection profile.