eloquent-churros-1fce9e[.]netlify[.]app
“Netflix India - Watch TV Shows Online, Watch Movies Online”
eloquent-churros-1fce9e.netlify.app — Inhalt nicht verfügbar. Markenidentität: Netflix; Betrugstyp: Generic Phishing. Zusammenfassung der Beweislage: VirusTotal 16/95 (ADMINUSLabs, Criminal IP, alphaMountain.ai, BitDefender, CyRadar); Google Safe Browsing flagged; CF Radar malicious; PhishDestroy score 100/100. Registrar: Netlify.
Die ausführliche Analyse von PhishDestroy AI bleibt auf Englisch, damit der ursprüngliche forensische Bericht unverändert bleibt.
Analysis of the domain eloquent-churros-1fce9e.netlify.app, observed on July 23, 2026, indicates a high‑risk brand‑impersonation campaign targeting Netflix users. The site resolves to the IP address 18.208.88.157, which belongs to Amazon.com, Inc. (AS14618) and is located in the United States. The domain is hosted on Netlify, as evidenced by the registration information and the presence of Netlify‑specific technology signatures and HTTP Strict Transport Security (HSTS) headers. The TLS certificate presented is issued by DigiCert Global G2 TLS RSA SHA256 2020 CA1 and is valid for the Netlify subdomain, confirming the hosting provider’s involvement. The page title returned by the server is “Netflix India – Watch TV Shows Online, Watch Movies Online,” directly referencing the Netflix brand.
However, the HTTP response code is 404, indicating that the content is no longer accessible. VirusTotal records show that 16 of 95 scanned security vendors flag the domain, and Google Safe Browsing classifies it as a social‑engineering threat. The domain appears on a single security blocklist and has been added to the PhishDestroy blocklist. Nameserver queries resolve to dns1.p04.nsone.net and dns2.p04.nsone.net, consistent with Netlify’s DNS configuration. Reputation services assign a trust score of 1 out of 100 on Scamadviser, reflecting extreme malicious intent.
The limited detection count and single blocklist entry suggest that the campaign may have been short‑lived or rapidly taken down, as the current status is reported offline. No additional evidence such as screenshot captures or malware samples has been released, leaving the exact phishing payload unknown. Defenders should block the domain at network perimeter and update proxy and DNS filtering policies to include both the fully qualified domain name and its resolved IP address. Continuous monitoring of Netlify‑hosted subdomains for similar brand‑themed titles is advised, as the infrastructure can be rapidly provisioned.
Sicherheitssignale
Erkenntnisse zur Netzwerksicherheit
Pipeline zur Reaktion auf Sicherheitsbedrohungen
Status der öffentlichen Sperrliste
Technologien · 2 identified
Netlify providers hosting and server-less backend services for web applications and static websites.
www.netlify.com 100 % KonfidenzHTTP Strict Transport Security (HSTS) informs browsers that the site should only be accessed using HTTPS.
www.rfc-editor.org 100 % KonfidenzVirusTotal-Analyse
Archivierte Beweise
Nachweise und externe Berichte
Wurden Sie von dieser Website betroffen?
Wenn Sie Kontoanmeldeinformationen, persönliche oder Zahlungsinformationen eingegeben oder eine Datei von dieser Domain heruntergeladen haben, ergreifen Sie sofort Maßnahmen. Nachfolgend finden Sie Ressourcen, die Ihnen helfen, den Vorfall zu melden und sich zu schützen.
Melden Sie sich bei Ihren örtlichen Behörden
Wählen Sie Ihr Land aus, um Offizielle Kontakte im Bereich Cyberkriminalität oder einen Beschwerdeentwurf erstellen → zu erhalten.
Jede beliebige Domain prüfen
Bedrohungsanalyse anhand gespeicherter Blocklisten, WHOIS, DNS und öffentlicher Scan-Beweise
Jetzt scannenPhishing melden
Melden Sie verdächtige Domains an unsere Bedrohungsdatenbank – schützen Sie die Community
MeldenEchtzeit-Bedrohungsfeed
Aktuelle Phishing-Meldungen und beobachtete Verfügbarkeitsänderungen
ÜberwachenBleiben Sie auf dem Laufenden, bleiben Sie sicher
Beobachten Sie aktuelle Bedrohungen oder legen Sie Widerspruch gegen diesen Eintrag ein, wenn Sie der Meinung sind, dass es sich um einen Fehlalarm handelt