# purefull.vip — SUSPICIOUS > purefull.vip is a Netflix clone hosting a live credential-stealing phishing page detected by 0/95 VirusTotal engines. Check the full report. ## Summary This domain poses an ongoing Netflix credential-stealing phishing operation. When visited, it displays a fake login page designed to trick users into surrendering their Netflix email and password to cybercriminals. Once harvested, the credentials are used to hijack streaming accounts, enabling attackers to stream content, change settings, or resell the premium access. Victims may also fall victim to follow-up identity theft or financial fraud if the same credentials were reused elsewhere. The page is still active and collecting credentials as you read this report. PhishDestroy identifies this threat through multiple indicators. The domain was created on March 25, 2024, and is registered with Dominet (HK) Limited. It resolves to IP address 163.181.214.129 and currently holds a legitimate Let’s Encrypt SSL certificate, which may provide a false sense of security to visitors. According to VirusTotal, it remains undetected by all 95 antivirus engines as of the latest scan. This low detection rate allows the scam to persist without immediate filtering by browsers or email providers. If you visited purefull.vip or entered your Netflix credentials, act now. Log in to your Netflix account from the official site and change your password immediately. Enable two-factor authentication if available. Run a full antivirus scan on any device where you reused the same email and password. Consider using a unique password for each online service to minimize risk. Report any fraudulent charges to your bank and monitor accounts for unusual activity. Avoid clicking links in any suspicious emails or messages claiming to be from Netflix. Always navigate directly to the official website to log in safely. ## Threat Details - Verdict: SUSPICIOUS - Site status: unknown (HTTP ?) ## Domain Intelligence - Registered: 2026-03-25 23:39:30 - Registrar: Dominet (HK) Limited - IP: 163.181.214.129 ## Detection Status - VirusTotal: 0 vendors flagged - Google Safe Browsing: clean - Blocklists: 0 hits ## Evidence - Cloudflare Radar: https://radar.cloudflare.com/scan/3745f1f0-a955-44fc-9adf-cd3f33813b4f - PhishDestroy: https://phishdestroy.io/domain/purefull.vip/ - LLM endpoint: https://phishdestroy.io/domain/purefull.vip/llm.txt ## If You Visited This Site 1. Change any passwords you may have entered 2. Enable 2FA on all related accounts 3. Monitor your accounts for unauthorized activity 4. Report to: FBI IC3, Europol, local authorities --- Report by PhishDestroy | https://phishdestroy.io/domain/purefull.vip/ Last updated: 2026-03-28