eventchecker-6a.netlify.app is currently flagged by PhishDestroy as a malicious site associated with generic phishing. The domain resolves to the IPv4 address 63.176.8.218, which is owned by Netlify’s hosting infrastructure. Registration details indicate the domain was created through Netlify, and no authoritative nameserver records could be retrieved, suggesting reliance on Netlify’s default DNS service. VirusTotal has processed the domain with scans from 91 antivirus vendors; none of the engines reported a detection at the time of analysis, but the absence of detections does not constitute confirmation of benign behavior.
The domain appears on a single external blocklist, reinforcing the view that security operators have observed suspicious activity linked to the hostname. No public Safe Browsing, Open Threat Exchange, or similar reputation feeds have surfaced additional signals, leaving those vectors inconclusive. SSL/TLS inspection shows a valid certificate issued to *.netlify.app, which is typical for sites hosted on the platform and does not provide authentication of the underlying content.
HTTP response headers and page title have not been disclosed, limiting visibility into the exact phishing lure employed. Given the confirmed association with a phishing blocklist, the presence of a Netlify‑hosted IP, and the lack of further mitigating evidence, defenders should continue to block the domain at network perimeter and endpoint layers, monitor for any related C2 traffic, and consider reporting the observation to additional threat intelligence sharing groups. Ongoing observation is recommended to detect any changes in hosting, content, or detection status that could alter the risk profile.