The domain positive-spots-703732.framer.app is currently classified as a high‑risk generic phishing site. Infrastructure analysis shows the hostname resolves to the IPv4 address 31.43.161.6, which is the sole IP observed for this indicator. Registration data attributes the domain to Framer B.V., a known registrar for the framer.app sub‑domain space, confirming that the attacker leveraged a legitimate hosting service to obtain a seemingly innocuous URL.
VirusTotal scans report that 16 of 91 security vendors have flagged the domain, indicating that multiple independent detection engines have identified malicious behavior. The domain is listed on one external security blocklist and is actively blocked by the PhishDestroy filtering service, demonstrating that threat‑intelligence feeds have already incorporated the indicator. Nameserver resolution failed (NS_NOT_FOUND), which may suggest a transient DNS configuration or intentional obfuscation of authoritative name servers.
The site remains active as of the report date, July 31, 2026, and no evidence of takedown has been observed. Defensive recommendations include adding the domain and its resolving IP address to outbound and inbound deny lists, updating URL filtering policies to encompass the framer.app sub‑domain range, and monitoring DNS traffic for queries to the domain. Security operations should also corroborate the detection with endpoint telemetry to assess any compromise attempts, and share the indicator with peer organizations to improve collective blocking coverage.