netflix-clone-eight-blond[.]vercel[.]app
“Clone of Netflix”
netflix-clone-eight-blond.vercel.app — Inhalt nicht verfügbar. Markenidentität: Apple; Betrugstyp: Tech Support Scam. Zusammenfassung der Beweislage: VirusTotal 21/94 (ADMINUSLabs, Criminal IP, BitDefender, CyRadar, ESET); URLQuery 4 alerts; Google Safe Browsing flagged; CF Radar malicious; PhishDestroy score 100/100. Registrar: Vercel.
Die ausführliche Analyse von PhishDestroy AI bleibt auf Englisch, damit der ursprüngliche forensische Bericht unverändert bleibt.
This domain netflix-clone-eight-blond.vercel.app is assessed as a high-risk brand impersonation infrastructure designed to deceive users by mimicking legitimate services while targeting Apple brand trust. The observed configuration indicates a credential phishing intent, where users may be lured into entering sensitive account information through a deceptive interface presented as a legitimate platform. Despite the misleading page title referencing a different service, threat intelligence indicates Apple impersonation as the primary targeting vector, suggesting cross-brand baiting to increase victim engagement and reduce suspicion. Such domains are typically used in staged phishing campaigns, where initial landing pages establish trust before redirecting or harvesting credentials.
This infrastructure is supported by multiple detection signals: VirusTotal classification shows 21/95 security vendors flagging the domain. The domain was registered through Vercel Inc. and created on March 08, 2026. It currently appears on 1 security blocklist, indicating active monitoring and confirmed malicious behavior. Network resolution points to IP address 216.198.79.67, hosted under US-based AS16509 Amazon.com, Inc. The SSL certificate is issued by Google Trust Services under WR1 profile, suggesting automated certificate provisioning common in rapidly deployed phishing infrastructure. These combined indicators show a recently created, actively hosted environment with cross-provider infrastructure usage typical of scalable phishing operations.
If a user has visited or interacted with this domain, immediate risk mitigation is required. Users should avoid entering any credentials or personal data and should assume any information submitted may be compromised. Passwords reused across other services should be changed immediately, and multi-factor authentication should be enabled where possible. Endpoint scans should be performed to detect potential malware or persistence mechanisms. Additionally, network-level monitoring for unusual login attempts or unauthorized access should be reviewed. Organizations should block the domain at DNS, proxy, and endpoint layers and add the indicators (domain, IP 216.198.79.67) to threat intelligence feeds. Given the active status of the infrastructure, continued monitoring is recommended to detect potential domain rotation or related impersonation clusters.
Erkenntnisse zur Netzwerksicherheit
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| Cloudflare DNS | netflix-clone-eight-blond.vercel.app |
malicious | Sinkholed |
| OpenDNS | netflix-clone-eight-blond.vercel.app |
phishing | Phishing Block |
| Quad9 DNS | netflix-clone-eight-blond.vercel.app |
malicious | Sinkholed |
| DNS4EU | netflix-clone-eight-blond.vercel.app |
malicious | Sinkholed |
Pipeline zur Reaktion auf Sicherheitsbedrohungen
Status der öffentlichen Sperrliste
Technologien · 2 identified
Vercel is a cloud platform for static frontends and serverless functions.
vercel.com 100 % KonfidenzHTTP Strict Transport Security (HSTS) informs browsers that the site should only be accessed using HTTPS.
www.rfc-editor.org 100 % KonfidenzVirusTotal-Analyse
Archivierte Beweise
Website-Performanceanalyse
Google PageSpeed Insights — mobile performance audit of netflix-clone-eight-blond.vercel.app · checked Mar 10, 2026
Nachweise und externe Berichte
Wurden Sie von dieser Website betroffen?
Wenn Sie Kontoanmeldeinformationen, persönliche oder Zahlungsinformationen eingegeben oder eine Datei von dieser Domain heruntergeladen haben, ergreifen Sie sofort Maßnahmen. Nachfolgend finden Sie Ressourcen, die Ihnen helfen, den Vorfall zu melden und sich zu schützen.
Melden Sie sich bei Ihren örtlichen Behörden
Wählen Sie Ihr Land aus, um Offizielle Kontakte im Bereich Cyberkriminalität oder einen Beschwerdeentwurf erstellen → zu erhalten.
Jede beliebige Domain prüfen
Bedrohungsanalyse anhand gespeicherter Blocklisten, WHOIS, DNS und öffentlicher Scan-Beweise
Jetzt scannenPhishing melden
Melden Sie verdächtige Domains an unsere Bedrohungsdatenbank – schützen Sie die Community
MeldenEchtzeit-Bedrohungsfeed
Aktuelle Phishing-Meldungen und beobachtete Verfügbarkeitsänderungen
ÜberwachenBleiben Sie auf dem Laufenden, bleiben Sie sicher
Beobachten Sie aktuelle Bedrohungen oder legen Sie Widerspruch gegen diesen Eintrag ein, wenn Sie der Meinung sind, dass es sich um einen Fehlalarm handelt