The domain magenta-designers-978286.framer.app is currently active and resolves to the IPv4 address 31.43.161.6. Registration records show the domain was created through Framer B.V., a provider associated with the framer.app hosting platform. The domain has been listed on a single security blocklist and is actively blocked by the PhishDestroy feed, indicating that at least one defensive community has identified it as malicious.
VirusTotal analysis shows that 13 of 91 scanned security vendors have flagged the domain, suggesting a non‑trivial detection consensus. The nameserver lookup returned NS_NOT_FOUND, which may reflect a misconfiguration or intentional omission to hinder DNS‑based mitigation. No additional metadata such as SSL certificate details, HTTP response codes, or page title has been published in the current intelligence set, leaving the exact phishing payload or targeted brand unspecified.
The combination of active DNS resolution, registration through a legitimate‑looking provider, blocklist presence, and multi‑vendor detections elevates the risk posture to high. Defenders should add the domain to outbound filtering rules, monitor DNS queries for the 31.43.161.6 address, and ensure that any user‑initiated connections to the framer.app sub‑domain are logged and inspected. Continuous re‑evaluation is advised, as further threat‑intel may emerge that clarifies the phishing campaign’s objectives or victim profile.