stunning-kulfi-2ae33b[.]netlify[.]app
“Naver Sign in”
stunning-kulfi-2ae33b.netlify.app — Contenuto non disponibile. Simulazione del marchio: Google; Tipo di truffa: Credential Phishing. Riepilogo delle prove: VirusTotal 16/92 (ADMINUSLabs, Criminal IP, BitDefender, ESET, Emsisoft); URLQuery 4 alerts; URLScan malicious verdict; Google Safe Browsing flagged; PhishDestroy score 100/100. Registrar: Netlify.
L’analisi dettagliata di PhishDestroy AI resta in inglese per preservare il rapporto forense originale.
This domain, stunning-kulfi-2ae33b.netlify.app, is assessed as a high-risk brand impersonation threat. The domain impersonates Google, attempting to deceive users into divulging sensitive information by presenting a misleading sign-in page that mimics the legitimate Google login interface. The domain’s deceptive page title 'Naver Sign in' further adds to the confusion, potentially leading users astray.
Analysis indicates that stunning-kulfi-2ae33b.netlify.app has been registered through Netlify and is hosted on an AWS EC2 instance located in Germany (eu-central-1), with the IP address 35.157.26.135. The SSL certificate is issued by DigiCert Inc, specifically the DigiCert Global G2 TLS RSA SHA256 2020 CA1. As of the latest data, 9 out of 95 security vendors on VirusTotal have flagged this domain as malicious. The domain appears on one security blocklist and is currently still active, despite being blocked by PhishDestroy. Google Safe Browsing has also identified this domain as a phishing site, indicating a significant risk to users who encounter it.
To mitigate the risks associated with this brand impersonation threat, users are advised to verify the URL of any sign-in page before entering credentials. Organizations should update their security awareness training to include examples of such deceptive tactics, ensuring employees recognize and avoid these types of phishing attempts. Additionally, network administrators should consider implementing DNS-based filtering and web proxy solutions to block access to this domain, thereby protecting users from potential credential theft and further malicious activities. Regular monitoring of network traffic for any attempts to access this domain can also help in early detection and response.
Informazioni sulla sicurezza di rete
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| Private YARA rules | wtm.pstatic.net/508e018/58b3e8e539ad7984d0de.js |
audit | Hunting_JS_WebAssembly |
| Private YARA rules | wtm.pstatic.net/39cb238/11b3bf3f99abd6f7c749.js |
audit | Hunting_JS_WebAssembly |
| OpenDNS | stunning-kulfi-2ae33b.netlify.app |
phishing | Phishing Block |
| DNS4EU | stunning-kulfi-2ae33b.netlify.app |
malicious | Sinkholed |
Pipeline di risposta alle minacce
Stato della lista di blocco pubblica
Tecnologie · 4 identified
Netlify providers hosting and server-less backend services for web applications and static websites.
www.netlify.com Confidenza al 100%jQuery CDN is a way to include jQuery in your website without actually downloading and keeping it your website's folder.
code.jquery.com Confidenza al 100%jQuery is a JavaScript library which is a free, open-source software designed to simplify HTML DOM tree traversal and manipulation, as well as event handling, CSS animation, and Ajax.
jquery.com Confidenza al 100%HTTP Strict Transport Security (HSTS) informs browsers that the site should only be accessed using HTTPS.
www.rfc-editor.org Confidenza al 100%Analisi di VirusTotal
Prove archiviate
Dati e relazioni esterne
Questo sito ti ha influenzato in qualche modo?
Se hai inserito credenziali dell'account, informazioni personali o di pagamento oppure hai scaricato un file da questo dominio, agisci immediatamente. Di seguito sono riportate le risorse per aiutarti a segnalare l'incidente e proteggerti.
Segnalalo alle autorità locali
Seleziona il tuo Paese per ottenere contatti ufficiali del crimine informatico o creare una bozza di reclamo →.
Verifica qualsiasi dominio
Analisi delle minacce utilizzando blocklist archiviate, WHOIS, DNS e prove di scansione pubblica
Scansiona oraSegnala un tentativo di phishing
Segnala i domini sospetti al nostro database delle minacce — proteggi la comunità
SegnalaFeed in tempo reale sulle minacce
Segnalazioni recenti di phishing e modifiche osservate della disponibilità
MonitoraRimani informato, rimani al sicuro
Controlla le minacce in tempo reale oppure contesta questa segnalazione se ritieni che si tratti di un falso positivo