Analysis of peaceful-copy-420603.framer.app shows that the domain is currently active and resolves to the IPv4 address 31.43.161.6. The registration record indicates the domain was created through Framer B.V., and the nameserver query returned NS_NOT_FOUND, suggesting that the authoritative name servers are either hidden or not publicly resolvable. The domain appears on a single security blocklist and has been explicitly blocked by the PhishDestroy feed, confirming that at least one reputable anti‑phishing service has identified it as malicious. VirusTotal data shows that 9 out of 91 scanned security vendors flagged the domain, providing independent corroboration of its malicious nature.
The threat type is classified as generic phishing, and the risk level has been assigned as high. No additional intelligence such as page title, SSL certificate details, HTTP response codes, or content analysis is available at this time, leaving the precise phishing payload and targeted brand undefined. Defenders should prioritize immediate containment by adding the domain to DNS‑level blocklists and updating intrusion‑prevention signatures that reference the observed IP address.
Continuous monitoring of the IP 31.43.161.6 for new hostnames or related activity is advised, as is periodic re‑query of VirusTotal and other reputation services for any changes in detection counts. Since the domain is already flagged by PhishDestroy, integrating that feed into security information and event management (SIEM) pipelines will ensure automated alerts on future resolution attempts. In the absence of further content details, threat‑hunting teams should focus on network indicators, correlate internal logs for connections to the IP, and enforce user awareness messaging that generic phishing attempts may originate from such infrastructure.