Analysis of amazonbyibrahim.netlify.app as of July 31, 2026 indicates the domain is still active and hosted on Netlify infrastructure. The domain resolves to the IPv4 address 35.157.26.135, and its authoritative name server information is unavailable (NS_NOT_FOUND). Registration through Netlify suggests the use of the provider’s automated deployment pipeline, a common vector for rapid phishing site provisioning.
The domain appears on a single security blocklist and is actively blocked by the PhishDestroy service, confirming that at least one downstream security product has identified it as malicious. VirusTotal scans show that 8 out of 91 security vendors flagged the domain, providing independent corroboration of suspicious behavior. No additional intelligence such as Safe Browsing status, Open Threat Exchange entries, SSL certificate details, HTTP response codes, or page title information is presently available, leaving the exact content and lure technique unverified.
Given the confirmed presence on a blocklist, multiple vendor detections, and the hosting pattern typical of phishing campaigns, defenders should treat the domain as high‑risk. Recommended actions include adding the domain to network and email denial lists, monitoring DNS queries for the associated IP address, and employing URL filtering to block any attempted resolution. Continuous re‑evaluation is advised, as further analysis of the landing page could reveal additional indicators of compromise.