This domain, disc0rdl0gin.netlify.app, is presently active and hosts a generic phishing campaign as indicated by multiple intelligence sources. Infrastructure analysis shows the domain resolves to the IP address 35.157.26.135, which is part of Netlify’s hosting platform; the registration was performed through Netlify, confirming the use of a legitimate cloud service for malicious purposes. No authoritative nameserver records are returned, suggesting the domain relies on Netlify’s default DNS configuration. VirusTotal scans have flagged the site, with five out of ninety‑one security vendors reporting malicious behavior, reinforcing the suspicion of phishing activity.
The domain is listed on a security blocklist and is actively blocked by PhishDestroy, demonstrating that at least one dedicated anti‑phishing service has taken mitigation steps. No additional public data such as Safe Browsing verdicts, Open Threat Exchange entries, SSL certificate details, HTTP response codes, trust‑score metrics, or page‑title information are currently available, leaving the full scope of the site’s content and target brand unverified. Defenders should treat any traffic to disc0rdl0gin.netlify.app as hostile. Immediate actions include adding the domain to internal blocklists, configuring web‑proxy or firewall rules to deny outbound connections, and monitoring DNS queries for the associated IP address.
Incident response teams should also query Netlify’s abuse contact to request takedown of the malicious site and continue to watch VirusTotal and other reputation services for any changes in detection counts. Because the domain leverages a reputable hosting provider, traditional URL filtering may miss it; therefore, network‑level controls that inspect resolved IPs and enforce deny‑list policies are recommended. Continuous threat‑intel feeds should be consulted to capture any new indicators that may emerge as the campaign evolves.