netfxversil[.]ip[.]18[.]190[.]176[.]77[.]nip[.]io
“Netflix”
netfxversil.ip.18.190.176.77.nip.io — Nicht bestätigt. Markenidentität: Google; Betrugstyp: Generic Phishing. Zusammenfassung der Beweislage: VirusTotal 10/91 (alphaMountain.ai, Chong Lua Dao, CyRadar, ESET, Forcepoint ThreatSeeker); URLScan malicious verdict; CF Radar malicious; PhishDestroy score 88/100. Registrar: NameCheap.
Die ausführliche Analyse von PhishDestroy AI bleibt auf Englisch, damit der ursprüngliche forensische Bericht unverändert bleibt.
The domain netfxversil.ip.18.190.176.77.nip.io was observed as an offline Google‑brand impersonation infrastructure. The site was flagged by PhishDestroy and appears on a single public blocklist. VirusTotal reports 11 detections out of 95 scanners, indicating that multiple security vendors have identified malicious activity associated with the host. DNS resolution maps the domain to the IPv4 address 18.190.176.77, which belongs to Amazon.com, Inc. (AS16509) and is geolocated in the United States.
The domain was created on 08 June 2012 and is registered through NameCheap, Inc. Its authoritative name servers are ns-do-sg.sslip.io, ns-hetzner.sslip.io, and ns-ovh.sslip.io, suggesting the use of third‑party DNS services to increase resilience. The MX record is configured to point back to the same domain, a pattern often employed to facilitate phishing‑related email delivery. No SSL/TLS certificate is presented, meaning the site would have been served over plain HTTP, which is atypical for modern credential‑harvesting portals but may have been intentional to avoid certificate costs or detection. The page title returned from the web server is “Netflix,” a discrepancy from the declared Google impersonation that could indicate a multi‑brand lure or a misconfiguration; the actual page content has not been captured, leaving the precise user‑facing experience uncertain.
Defenders should add the domain and its associated IP address to network‑level deny lists, enforce outbound DNS filtering for the listed nameservers, and monitor for any future re‑registration of the domain or similar sub‑domains under the same registrar. Email security controls should be updated to reject messages originating from the domain’s MX host, and any existing mailbox rules that reference the domain should be reviewed.
Erkenntnisse zur Netzwerksicherheit
Pipeline zur Reaktion auf Sicherheitsbedrohungen
Status der öffentlichen Sperrliste
VirusTotal-Analyse
Archivierte Beweise
Nachweise und externe Berichte
Wurden Sie von dieser Website betroffen?
Wenn Sie Kontoanmeldeinformationen, persönliche oder Zahlungsinformationen eingegeben oder eine Datei von dieser Domain heruntergeladen haben, ergreifen Sie sofort Maßnahmen. Nachfolgend finden Sie Ressourcen, die Ihnen helfen, den Vorfall zu melden und sich zu schützen.
Melden Sie sich bei Ihren örtlichen Behörden
Wählen Sie Ihr Land aus, um Offizielle Kontakte im Bereich Cyberkriminalität oder einen Beschwerdeentwurf erstellen → zu erhalten.
Jede beliebige Domain prüfen
Bedrohungsanalyse anhand gespeicherter Blocklisten, WHOIS, DNS und öffentlicher Scan-Beweise
Jetzt scannenPhishing melden
Melden Sie verdächtige Domains an unsere Bedrohungsdatenbank – schützen Sie die Community
MeldenEchtzeit-Bedrohungsfeed
Aktuelle Phishing-Meldungen und beobachtete Verfügbarkeitsänderungen
ÜberwachenBleiben Sie auf dem Laufenden, bleiben Sie sicher
Beobachten Sie aktuelle Bedrohungen oder legen Sie Widerspruch gegen diesen Eintrag ein, wenn Sie der Meinung sind, dass es sich um einen Fehlalarm handelt