Analysis of eventchecker-ko.netlify.app indicates that the domain is actively being used in a credential‑harvesting campaign. The site is hosted on Netlify infrastructure and resolves to the IPv4 address 63.176.8.218. VirusTotal records show that the domain was submitted to 91 scanning engines; none of the engines returned a detection at the time of the scan. Independent community blocklists have flagged the domain, with PhishDestroy already listing it as blocked, and it appears on one additional security blocklist.
The registrar information confirms the domain was provisioned through Netlify, and DNS queries return no identifiable nameserver records (NS_NOT_FOUND), which limits visibility into the authoritative DNS configuration. No public SSL certificate details, HTTP status codes, or page‑title metadata have been disclosed, leaving the exact content of the landing page unverified. Consequently, the primary observable indicators are the hosting IP, the Netlify registration, and the presence on blocklists.
Defenders should treat the domain as high‑confidence malicious, update URL filtering and DNS sinkhole rules to deny resolution, and monitor network traffic for connections to 63.176.8.218. Continuous re‑scanning on VirusTotal and periodic checks against emerging blocklists are recommended to capture any changes in detection status. Because the site’s payload and target brand are not yet identified, threat‑hunting teams should look for typical credential‑theft patterns such as POST requests containing usernames and passwords, and correlate any suspicious authentication attempts with the domain’s IP address.