# PhishDestroy threat dossier — netfliclonebyrohit.netlify.app ================================================================ Fetched: 2026-07-30 13:39:13 UTC Canonical: https://phishdestroy.io/domain/netfliclonebyrohit.netlify.app/ ## VERDICT ---------------------------------------------------------------- HIGH THREAT — malicious activity confirmed Composite threat score: 75/100 (PhishDestroy scoring — see methodology below) ## DETECTION EVIDENCE ---------------------------------------------------------------- VirusTotal: 14/91 security vendors flagged this domain Flagging vendors: alphaMountain.ai, BitDefender, ESET, Emsisoft, Fortinet, G-Data, Google Safe Browsing, Kaspersky, LevelBlue, Lionic, Netcraft, Sophos, VIPRE, Webroot Public blocklists: listed on 1 independent blocklist Google Safe Browsing: FLAGGED ## INFRASTRUCTURE ---------------------------------------------------------------- IP address: 35.157.26.135 Registrar: Netlify Nameservers: NS_NOT_FOUND ## TLS CERTIFICATE ---------------------------------------------------------------- Issuer: DigiCert Inc / DigiCert Global G2 TLS RSA SHA256 2020 CA1 Expires: 2027-03-19 Status: INVALID chain Fingerprint: bc3a8134c21a842e64ea34d488826dd2ba50f59a3bcbaed1e6b71a4242de1478 Subject Alternative Names (related infrastructure — often same operator): - netlify.app ## ABUSE-REPORT HISTORY (evidence of registrar non-response) ---------------------------------------------------------------- Status: pending notification queue. No abuse reports filed yet — this domain is waiting for the next cycle of our automated abuse-reporter. ## TIMELINE ---------------------------------------------------------------- First detected: 2026-07-30 14:17:41 UTC (by PhishDestroy tracker) Last verified: 2026-07-30 15:02:05 UTC Current status: ACTIVE / observable ## EXTERNAL CORROBORATION (third-party evidence) ---------------------------------------------------------------- URLScan.io: https://urlscan.io/result/019fb2f4-4b11-77bd-b4b1-60357f676c02/ Wayback Machine: https://web.archive.org/web/*/netfliclonebyrohit.netlify.app crt.sh CT logs: https://crt.sh/?q=%25.netfliclonebyrohit.netlify.app Google transparency: https://transparencyreport.google.com/safe-browsing/search?url=netfliclonebyrohit.netlify.app AlienVault OTX: https://otx.alienvault.com/indicator/domain/netfliclonebyrohit.netlify.app URLhaus: https://urlhaus.abuse.ch/host/netfliclonebyrohit.netlify.app/ ## ANALYST NARRATIVE ---------------------------------------------------------------- [Generated: 2026-07-30 14:19:09 UTC — narrative may predate facts above. Treat fields in TIMELINE / DETECTION EVIDENCE / INFRASTRUCTURE as authoritative if they differ from the prose below.] netfliclonebyrohit.netlify.app used for credential theft The domain netfliclonebyrohit.netlify.app is currently active and has been identified as a high‑risk credential‑theft operation. Google Safe Browsing has flagged the site for social engineering, indicating that it is likely employed to lure users into revealing personal data. Independent threat‑intelligence feeds have corroborated this assessment: PhishDestroy lists the domain as blocked, and one public security blocklist also contains it. The domain resolves to the IP address 35.157.26.135, which belongs to Netlify’s hosting infrastructure; Netlify is also recorded as the registrar, confirming that the site is hosted on a legitimate cloud‑service platform often abused by malicious actors. VirusTotal analysis shows that 14 of 91 scanned security vendors have flagged the domain, providing additional evidence of malicious behavior. Nameserver information is unavailable, which limits visibility into the domain’s DNS configuration. No further technical details such as SSL certificate attributes, HTTP response codes, or page titles have been published, leaving the exact content and lure technique unverified. Defenders should prioritize the immediate addition of netfliclonebyrohit.netlify.app to URL filtering, DNS sink‑hole, and endpoint protection rules. Network monitoring should include the associated IP 35.157.26.135 to detect any outbound connections originating from internal assets. Continuous re‑evaluation of the domain’s status is advised, as threat actors frequently shift hosting or employ fast‑flux techniques. Organizations are encouraged to share any observed traffic or infection indicators with upstream blocklist providers to improve collective detection coverage. ## EVIDENCE HASHES ---------------------------------------------------------------- TLS cert SHA-256: bc3a8134c21a842e64ea34d488826dd2ba50f59a3bcbaed1e6b71a4242de1478 ## SCORING METHODOLOGY ---------------------------------------------------------------- Composite score is NOT derived from VirusTotal alone. PhishDestroy aggregates: - VirusTotal positive ratio - Public blocklist consensus (MetaMask, ScamSniffer, OpenPhish, PhishTank, URLhaus, CryptoFirewall, SEAL, Polkadot, Enkrypt, Phishunt, DiscordPhishing, PhishingDB) - Cloaking detection (HTTP 666 or rendering delta between bot and real visitor) - DNS-filter consensus (Quad9, CleanBrowsing, NextDNS, AdGuard, Cloudflare, etc.) - AlienVault OTX pulses + Cloudflare Radar + Google Safe Browsing - URLScan / URLQuery verdicts - Brand-impersonation heuristics (DOM analysis of forms, logos, wording) - Known phishing-kit fingerprinting (favicon hash, JS obfuscation signatures) - Wallet-drainer family classification (Angel, MS, Rainbow, Pink, Inferno, ...) - Free-TLS vs paid-cert ratio (throwaway infrastructure signal) - Registrar/hosting abuse history (this registrar's track record) - Human researcher sign-off (operator takedown team) A domain present in our database is ALREADY flagged. A low VT count by itself does NOT mean the domain is safe — new scam domains routinely show 0/95 VT for their first 7–30 days while actively draining wallets. Always cross-reference the composite score and the individual indicators above, not just VT. ## CORRECTIONS / APPEALS ---------------------------------------------------------------- Full HTML report: https://phishdestroy.io/domain/netfliclonebyrohit.netlify.app/ JSON API: https://api.destroy.tools/v1/check?domain=netfliclonebyrohit.netlify.app Appeal a flag: https://phishdestroy.io/appeals/ (responded to within 48 hours, FP rate <0.01%) Submit a report: https://t.me/PhishDestroy_bot About PhishDestroy: independent open-source threat-intelligence platform. Tracked: 195,828 domains (83,526 alive under monitoring, 110,042 confirmed takedowns/dead). Site: https://phishdestroy.io