Analysis of the domain flixorbit-login.netlify.app indicates that it is actively being used for credential phishing. The site is hosted on Netlify infrastructure and resolves to the IP address 35.157.26.135. Registration data shows the domain was provisioned through Netlify, and no authoritative name server information is available. The domain is currently listed on one public security blocklist and has been explicitly blocked by the PhishDestroy service, confirming its malicious intent.
VirusTotal scans reveal that ten out of ninety‑one security vendors have flagged the domain as malicious, providing independent corroboration of its threat profile. The threat type is identified as credential phishing, and the risk level is assessed as high. While the page title, SSL certificate details, HTTP response codes, and Safe Browsing status have not been disclosed, the available evidence is sufficient to consider the domain unsafe.
Defenders should block the domain at network perimeter, update intrusion detection signatures, and add the associated IP address to host‑based deny lists. Continuous monitoring of the IP and any related Netlify sub‑domains is advised, as the attacker may pivot to additional resources. Organizations should educate users about the risk of unsolicited login prompts that reference this domain, and enforce multi‑factor authentication to mitigate credential compromise.