Analysis indicates that the domain aqua-millions-761930.framer.app resolves to the IPv4 address 31.43.161.6. The hosting appears to be provided by the Framer platform, as the registrar is listed as Framer B.V. No authoritative name server information could be retrieved (NS_NOT_FOUND), which may hinder typical DNS‑based mitigation. The domain is presently active and has been listed on two public phishing blocklists. Specifically, it is blocked by PhishDestroy and OpenPhish, confirming that at least two independent feed providers have observed malicious activity associated with this host.
VirusTotal scans have returned 18 positive detections out of 91 submitted security engines, reinforcing the suspicion of malicious intent. The available intelligence does not contain a page title, SSL certificate details, HTTP response codes, or any other content‑based indicators, so the exact nature of the hosted page remains unknown. Likewise, no attribution to a particular phishing kit or targeted brand is provided. The lack of visible metadata limits the ability to confirm the exact payload or credential‑harvesting mechanism, but the classification as a generic phishing operation is supported by the blocklist entries and the detection ratio.
Defenders should treat the domain as high‑risk. Immediate actions include adding 31.43.161.6 and the fully qualified domain name to network‑level deny lists, updating web‑proxy and DNS filtering policies to block traffic to both the IP and the domain, and monitoring for any outbound connections that may be attempting to reach this host. Because the domain is hosted on a legitimate SaaS platform, investigators may consider contacting Framer’s abuse handling team to request takedown or remediation. Continuous re‑evaluation is advised, as additional content analysis or threat‑intel feeds could surface further indicators.