http://deluxe-tulumba-c77932.netlify.app/HTTP 404
3.1 KB
1.4 KB
0 internal · 1 external
Content-Type: text/htmlServer: NetlifyAll stored response-header names (5)
Content-TypeDateServerX-Nf-Request-IdTransfer-Encoding“Підключення Phantom-гаманця”
deluxe-tulumba-c77932.netlify.app — Contenido no disponible. Suplantación de marca: Phantom; Tipo de estafa: Credential Phishing. Resumen de las pruebas: VirusTotal 3/91 (alphaMountain.ai, Gridinsoft, LevelBlue); Google Safe Browsing flagged; Spamhaus DBL_ABUSED_PHISH; 2 external blocklist matches (MetaMask, SEAL); PhishDestroy score 80/100. Registrador: Netlify.
El análisis detallado de PhishDestroy AI se mantiene en inglés para conservar el registro forense original.
The domain deluxe-tulumba-c77932.netlify.app is presently active and has been identified as a high‑risk credential‑harvesting site. Google Safe Browsing classifies the URL under social engineering, indicating it is likely used to deceive users into submitting sensitive information. VirusTotal analysis records three detections out of ninety‑one scanning engines, confirming that multiple security products have flagged the domain as malicious. Independent blocklist providers PhishDestroy, MetaMask, and SEAL have each listed the address, and the domain appears on three additional security blocklists, reinforcing its reputation as a threat vector.
Infrastructure inspection shows the domain is hosted on Netlify, a popular static‑site and serverless platform, and resolves to the IPv4 address 63.176.8.218. The nameserver information is unavailable (NS_NOT_FOUND), which is typical for Netlify‑hosted sites that rely on the provider’s managed DNS. No SSL certificate details or HTTP response codes have been disclosed, and the page title and content have not been publicly analyzed, leaving the exact phishing lure undefined. Defenders should treat any traffic to this host as malicious.
Immediate actions include adding the domain to DNS blocklists, configuring web proxies to deny HTTP/HTTPS requests, and updating endpoint security signatures to incorporate the three VirusTotal detections. Continuous monitoring of the IP 63.176.8.218 for anomalous connections is advised, as Netlify may host multiple unrelated sites on the same address. Because the site remains active, threat hunters should consider sinkholing the domain where possible and sharing observed indicators of compromise with community blocklists to accelerate broader protection.
Netlify providers hosting and server-less backend services for web applications and static websites.
www.netlify.com 100 % de confianzaHTTP Strict Transport Security (HSTS) informs browsers that the site should only be accessed using HTTPS.
www.rfc-editor.org 100 % de confianzaGoogle PageSpeed Insights — mobile performance audit of deluxe-tulumba-c77932.netlify.app · checked Jul 28, 2026
Timestamped response metadata retained by the local collection pipeline. Each value below belongs to the displayed archive time.
http://deluxe-tulumba-c77932.netlify.app/Content-Type: text/htmlServer: NetlifyContent-TypeDateServerX-Nf-Request-IdTransfer-EncodingSi ingresó credenciales de cuenta, información personal o de pago, o descargó un archivo de este dominio, tome medidas inmediatas. A continuación encontrará recursos que le ayudarán a informar el incidente y protegerse.
Seleccione su país para obtener contactos oficiales de cibercrimen o crear un borrador de queja →.
Análisis de amenazas utilizando listas de bloqueo almacenadas, WHOIS, DNS y evidencia de escaneo público
Escanear ahoraEnvía los dominios sospechosos a nuestra base de datos de amenazas: protege a la comunidad
DenunciarInformes de phishing recientes y cambios de disponibilidad observados
MonitorizarSupervisa las amenazas en tiempo real o impugna esta entrada si crees que se trata de un falso positivo.