The domain illuminated-monstera-424472.framer.app is currently active and has been identified as a generic phishing site. Infrastructure analysis shows the domain is registered through Framer B.V. and resolves to the IPv4 address 31.43.160.6. DNS queries return no authoritative nameserver information (NS_NOT_FOUND), suggesting either a misconfiguration or intentional obfuscation of the hosting environment. The site has been blocked by the PhishDestroy sinkhole, indicating that at least one defensive network has taken remediation action.
VirusTotal scans report that 17 of 91 security vendors flag the domain as malicious, providing a moderate consensus of risk across the scanning community. Additionally, the domain appears on a single external blocklist, further confirming its presence on threat intelligence feeds. No additional context such as page title, brand target, or specific phishing kit is available, so the exact victim lure remains undefined. Given the active status, defenders should proactively deny any outbound connections to 31.43.160.6 and add the fully qualified domain name to local DNS blocklists.
Continuous monitoring of DNS query logs for the illuminated-monstera-424472.framer.app pattern is advised, as well as inclusion of the domain in email gateway and web proxy filtering rules. Organizations using threat‑intelligence platforms should ingest the reported detection count and blocklist presence to improve correlation with internal alerts. The combination of registrar information, IP resolution, and multi‑vendor detection makes this domain a high‑confidence indicator of phishing activity that warrants immediate mitigation.