This domain, quiet-tulip-244862.framer.app, is currently active and resolves to the IPv4 address 31.43.161.6. Registration information shows the domain was created through Framer B.V., a provider of web‑hosting and site‑builder services, which is consistent with the use of the framer.app sub‑domain. DNS queries return no nameserver records (NS_NOT_FOUND), indicating either a misconfiguration or a dynamically managed DNS setup.
The domain appears on one public security blocklist and has been explicitly blocked by the PhishDestroy feed, demonstrating that at least one anti‑phishing organization has identified it as malicious. VirusTotal analysis reports that eight of ninety‑one scanning engines flag the domain as malicious, providing independent confirmation of its threat nature. No additional context such as page title, targeted brand, or observed payload is available in the current intelligence set.
Consequently, the precise phishing lure employed by the site remains uncertain. Given the confirmed malicious classification, defenders should deny outbound connections to 31.43.161.6, add quiet-tulip-244862.framer.app to DNS‑based blocklists, and incorporate the indicator into network intrusion detection signatures. Continuous monitoring of the IP address for any new activity and sharing of this indicator with broader threat‑intel communities are recommended to mitigate potential exploitation.