On 31 July 2026 the domain closestone.netlify.app was observed hosting a generic phishing campaign. The site remains active and is currently blocked by the PhishDestroy filtering service. Registration data shows the domain was provisioned through Netlify, a cloud‑hosting platform that also supplies DNS for the site; the authoritative name server could not be resolved (NS_NOT_FOUND). Network resolution points to the IPv4 address 35.157.26.135, which belongs to the Netlify infrastructure and is shared among numerous unrelated sites, limiting the value of host‑based attribution.
The domain is listed on a single public blocklist, indicating that at least one external sinkhole or reputation service has flagged it. VirusTotal analysis returned six positive detections out of ninety‑one scanners, confirming that multiple security engines consider the content malicious. No additional intelligence such as Safe Browsing status, OTX reports, SSL certificate details, HTTP response codes, or page‑title metadata is available at this time, leaving the exact lure and victim‑targeting tactics undocumented. Given the confirmed activity, defenders should ensure that any outbound traffic to the IP 35.157.26.135 is monitored and, where possible, blocked at the network perimeter.
Endpoint protection solutions should be updated with the domain indicator and the six VirusTotal‑reported signatures. Organizations employing web‑filtering or DNS‑filtering services are advised to add closestone.netlify.app to their deny lists and to share the indicator with threat‑intel sharing platforms to improve collective visibility. Continuous re‑inspection of the host is recommended, as Netlify‑hosted domains can change content rapidly.