On July 30, 2026, the domain magnificent-caramel-e8de44.netlify.app was observed as an active generic phishing infrastructure. The domain resolves to the IPv4 address 35.157.26.135, which belongs to Netlify’s hosting platform. Registration was performed through Netlify, and the nameserver lookup returned no records, indicating that standard DNS delegation information is unavailable.
The domain appears on two independent phishing blocklists, specifically PhishDestroy and OpenPhish, confirming its use in credential‑harvesting campaigns. VirusTotal has processed the domain and 20 of the 91 scanned security vendors returned a malicious classification, reinforcing the blocklist findings. No additional intelligence such as page title, SSL certificate details, or HTTP response codes is currently available, leaving the exact content and targeted brand of the phishing page undocumented.
Given the convergence of blocklist listings and multiple vendor detections, the infrastructure should be considered high‑risk. Defenders are advised to block the domain and the associated IP address at perimeter and DNS layers, monitor for any new resolution changes, and incorporate the domain into threat‑intel feeds used by security tooling. Continuous re‑evaluation is recommended in case further analysis uncovers additional indicators such as specific credential‑stealing kits or targeted brands.