# netlfixclone.vercel.app — MALICIOUS > netlfixclone.vercel.app is a verified crypto drainer impersonating Netflix with a 23/95 VirusTotal score. Block it now and verify on PhishDestroy ## Summary PhishDestroy identifies netlfixclone.vercel.app as an active crypto-draining phishing domain that impersonates Netflix to steal user credentials and digital assets. The domain hosts a fraudulent login portal designed to harvest Netflix account details and associated payment information before exfiltrating cryptocurrency from connected wallets. Behavioral analysis confirms the presence of a drainer kit that silently requests wallet connections and initiates unauthorized transfers upon authentication. This domain was flagged with a high-risk score of 23/95 by security vendors on VirusTotal and is listed by Google Safe Browsing under SOCIAL_ENGINEERING. It was registered through Vercel Inc., resolves to IP address 216.198.79.3, and is blocked by 1 security blocklist including OpenPhish. SSL encryption is provided by Google Trust Services, indicating an attempt to appear legitimate. The campaign remains active as of the latest scan. Immediate response includes blocking the domain at the network perimeter and advising users not to interact with any links or attachments related to netlfixclone.vercel.app. Despite active takedown efforts, residual risk persists due to rapid domain rotation and hosting flexibility on Vercel’s platform. Users are strongly advised to verify any unsolicited login prompts using PhishDestroy before entering credentials. ## Threat Details - Verdict: MALICIOUS - Site status: unknown (HTTP ?) ## Domain Intelligence - Registrar: Vercel Inc. - IP: 216.198.79.3 ## Detection Status - VirusTotal: 23 vendors flagged - Google Safe Browsing: FLAGGED - Blocklists: 1 hits Lists: ["OpenPhish"] ## Evidence - Cloudflare Radar: https://radar.cloudflare.com/scan/6a8dc1c8-c918-497b-b200-774e23c69f28 - PhishDestroy: https://phishdestroy.io/domain/netlfixclone.vercel.app/ - LLM endpoint: https://phishdestroy.io/domain/netlfixclone.vercel.app/llm.txt ## If You Visited This Site 1. Change any passwords you may have entered 2. Enable 2FA on all related accounts 3. Monitor your accounts for unauthorized activity 4. Report to: FBI IC3, Europol, local authorities --- Report by PhishDestroy | https://phishdestroy.io/domain/netlfixclone.vercel.app/ Last updated: 2026-03-31