netflix[.]mrszmr[.]hu
“Deployment Unavailable”
netflix.mrszmr.hu — Inhalt nicht verfügbar. Markenidentität: Netflix; Betrugstyp: Generic Phishing. Zusammenfassung der Beweislage: VirusTotal 15/95 (ADMINUSLabs, Criminal IP, BitDefender, CyRadar, ESET); URLScan malicious verdict; CF Radar malicious; PhishDestroy score 95/100.
Die ausführliche Analyse von PhishDestroy AI bleibt auf Englisch, damit der ursprüngliche forensische Bericht unverändert bleibt.
This domain, netflix.mrszmr.hu, was identified as a brand impersonation threat targeting Netflix, with elevated risk indicators as of July 23, 2026. Analysis reveals the domain is currently offline, returning an HTTP 404 status with a page title of 'Deployment Unavailable.' The domain appears on one security blocklist (PhishDestroy) and is flagged by 15 of 95 security vendors in VirusTotal, though the specific detection context remains unverified. Infrastructure analysis shows the domain previously resolved to IP 216.198.79.1, hosted on Amazon.com, Inc. (AS16509) in the US. The SSL certificate is issued by Let's Encrypt (R12), a common choice for both legitimate and malicious domains.
Technologies detected include Vercel and HSTS, which may indicate an attempt to appear legitimate or leverage cloud-based hosting for scalability. Notably, the domain's nameservers are unresolvable (NS_NOT_FOUND), a potential red flag for ephemeral or misconfigured infrastructure. Defenders should treat this domain as a confirmed phishing threat due to its association with Netflix impersonation, blocklist inclusion, and vendor detections. The 404 status suggests the campaign may be dormant or undergoing infrastructure changes, but historical resolution and detection data justify continued monitoring.
Network-level blocking of the IP (216.198.79.1) and domain is recommended, along with alerting users to potential Netflix-themed phishing attempts. Further investigation into the hosting provider (Amazon AS16509) and SSL certificate chain may reveal additional linked infrastructure. No evidence of a phishing kit or exact content is available, limiting attribution to specific threat actors or campaign tactics.
Erkenntnisse zur Netzwerksicherheit
Pipeline zur Reaktion auf Sicherheitsbedrohungen
Status der öffentlichen Sperrliste
Technologien · 2 identified
Cloud platform for frontend deployment, optimized for Next.js.
HTTP Strict Transport Security — forces browsers to use HTTPS connections only.
VirusTotal-Analyse
Archivierte Beweise
Nachweise und externe Berichte
Wurden Sie von dieser Website betroffen?
Wenn Sie Kontoanmeldeinformationen, persönliche oder Zahlungsinformationen eingegeben oder eine Datei von dieser Domain heruntergeladen haben, ergreifen Sie sofort Maßnahmen. Nachfolgend finden Sie Ressourcen, die Ihnen helfen, den Vorfall zu melden und sich zu schützen.
Melden Sie sich bei Ihren örtlichen Behörden
Wählen Sie Ihr Land aus, um Offizielle Kontakte im Bereich Cyberkriminalität oder einen Beschwerdeentwurf erstellen → zu erhalten.
Jede beliebige Domain prüfen
Bedrohungsanalyse anhand gespeicherter Blocklisten, WHOIS, DNS und öffentlicher Scan-Beweise
Jetzt scannenPhishing melden
Melden Sie verdächtige Domains an unsere Bedrohungsdatenbank – schützen Sie die Community
MeldenEchtzeit-Bedrohungsfeed
Aktuelle Phishing-Meldungen und beobachtete Verfügbarkeitsänderungen
ÜberwachenBleiben Sie auf dem Laufenden, bleiben Sie sicher
Beobachten Sie aktuelle Bedrohungen oder legen Sie Widerspruch gegen diesen Eintrag ein, wenn Sie der Meinung sind, dass es sich um einen Fehlalarm handelt