On July 31, 2026 the domain project-sub31.netlify.app was identified as a high-risk generic phishing site. The domain is hosted on Netlify and resolves to the IPv4 address 35.157.26.135. It appears on a single security blocklist, where it is listed by PhishDestroy, and Google Safe Browsing classifies it as a social-engineering threat.
VirusTotal analysis shows that six of ninety-one scanned security vendors flagged the domain as malicious, reinforcing the suspicion of phishing activity. The registrar information indicates the domain was provisioned through Netlify’s automated registration service; no authoritative nameserver records were retrieved, suggesting possible reliance on Netlify’s default DNS configuration. The current status is active, and the unique seed e50d34 links this observation to a broader intelligence set.
While the available data confirms the presence of malicious indicators, the exact phishing payload, targeted brand, or credential-harvesting page content has not been publicly disclosed. Consequently, defensive teams should block traffic to the domain at network perimeter devices, add the domain to local deny lists, and monitor for any outbound connections to the associated IP address. Continuous re-scanning with multi-vendor engines is recommended to capture any changes in detection rates, and analysts should correlate any related incidents with the identified seed to improve attribution.