netflix-clone-mu-seven[.]vercel[.]app
“Netflix”
netflix-clone-mu-seven.vercel.app — Contenu indisponible. Usurpation de l'identité de la marque : Apple; Type d'arnaque : Tech Support Scam. Résumé des preuves: VirusTotal 23/94 (ADMINUSLabs, Criminal IP, alphaMountain.ai, BitDefender, CyRadar); URLScan malicious verdict; Google Safe Browsing flagged; PhishDestroy score 100/100. Bureau d’enregistrement: Vercel.
L’analyse détaillée de PhishDestroy AI reste en anglais afin de préserver le relevé forensique original.
The domain netflix-clone-mu-seven.vercel.app was registered on March 08, 2026 through Vercel Inc. and resolves to the Amazon‑owned IP address 216.198.79.3 (AS16509, United States). The site presented a TLS certificate issued by Google Trust Services under the WR1 name, indicating a valid HTTPS endpoint despite the malicious intent. HTTP responses returned a 451 status, signalling that the resource is unavailable for legal reasons, which aligns with the current offline state reported by defenders. Google Safe Browsing has flagged the domain for social engineering, and the site appears on one external security blocklist.
Independent threat‑intelligence feeds, including PhishDestroy, have already blocked the domain, confirming active mitigation. VirusTotal analysis shows that 23 of 94 scanning engines label the host as malicious, and the Gridinsoft trust score of 0 / 100 reinforces the high‑risk assessment. Scamadviser assigns a trust score of 1 / 100, reflecting the negligible reputation of the domain. The page title returned "Netflix," yet the known intelligence categorises the operation as a tech‑support scam that impersonates Apple, indicating a deliberate brand‑mixing tactic to lure victims.
While the exact payload or victim interaction flow has not been publicly disclosed, the convergence of multiple detection sources, low trust metrics, and the presence of a legitimate‑looking certificate suggest a sophisticated social‑engineering campaign. Defenders should continue to block the domain at perimeter and DNS layers, monitor for any re‑registration attempts, and update incident response playbooks to include Apple‑related tech‑support lure scenarios. Further analysis of any captured traffic or payloads would be required to detail the specific ransomware or credential‑harvesting mechanisms employed.
Processus de réponse aux menaces Pipeline
Statut de la liste de blocage publique
Analyse VirusTotal
Preuves archivées
Analyse des performances du site
Google PageSpeed Insights — mobile performance audit of netflix-clone-mu-seven.vercel.app · checked Mar 10, 2026
Données factuelles et rapports externes
Ce site vous a-t-il affecté ?
Si vous avez saisi des informations d'identification de compte, des informations personnelles ou de paiement, ou téléchargé un fichier à partir de ce domaine, agissez immédiatement. Vous trouverez ci-dessous des ressources pour vous aider à signaler l'incident et à vous protéger.
Signalez-le à vos autorités locales
Sélectionnez votre pays pour obtenir contacts officiels en matière de cybercriminalité ou créer un projet de plainte →.
Vérifier n'importe quel domaine
Analyse des menaces à l'aide de listes de blocage stockées, de WHOIS, de DNS et de preuves d'analyse publique
Scanner maintenantSignaler une tentative d'hameçonnage
Signalez les domaines suspects à notre base de données des menaces — protégez la communauté
SignalerFlux d'alertes en temps réel
Rapports de phishing récents et changements de disponibilité observés
SurveillerRestez informés, restez en sécurité
Surveillez les menaces en temps réel ou signalez cette alerte si vous pensez qu'il s'agit d'un faux positif