The domain make-courgette-949087.framer.app is currently active and has been identified as a generic phishing infrastructure. It resolves to the IPv4 address 31.43.160.6 and is hosted under the registrar Framer B.V., indicating that the domain was provisioned through the Framer platform. The domain appears on a single security blocklist and is explicitly listed as blocked by the PhishDestroy feed, confirming that at least one anti‑phishing community has taken mitigation action. VirusTotal analysis shows that nine of ninety‑one scanning engines have reported malicious activity, providing additional independent confirmation of its phishing nature.
No nameserver records were returned in the intelligence set, which limits visibility into the authoritative DNS configuration and may hinder attribution efforts. The limited blocklist presence suggests that the domain is either newly deployed or being used in a targeted manner, and the modest VirusTotal detection count indicates that not all scanners have yet flagged the content. Because the site’s page title, HTTP response details, SSL certificate information, and any associated threat‑intel identifiers (such as OTX or Safe Browsing entries) are not available, the full scope of the phishing campaign cannot be precisely mapped at this time.
Defenders should immediately add 31.43.160.6 to network‑level deny lists, enforce DNS‑based blocking of the domain, and monitor for any related sub‑domains or IP aliases that may appear in future feeds. Continuous re‑scanning on VirusTotal and inclusion in internal sandbox environments are recommended to capture any evolving payloads or credential‑harvesting pages. Organizations that rely on the Framer hosting service should verify that no legitimate assets are inadvertently sharing the same IP range, and consider applying stricter outbound filtering to mitigate exposure to this malicious endpoint.