cozy-tartufo-66895a[.]netlify[.]app
“Site not found”
cozy-tartufo-66895a.netlify.app — 콘텐츠를 사용할 수 없음. 브랜드 사칭: Facebook. 증거 요약: VirusTotal 16/91 (Criminal IP, alphaMountain.ai, BitDefender, Chong Lua Dao, CyRadar); URLScan malicious verdict; PhishDestroy score 95/100. 등록기관: Netlify.
원본 포렌식 기록을 보존하기 위해 아래의 상세 PhishDestroy AI 분석은 영어로 유지됩니다.
Analysis of the domain cozy-tartufo-66895a.netlify.app shows that it resolves to the IP address 35.157.26.135 and is hosted on Netlify’s infrastructure, as indicated by the registrar information. The domain was created on May 08, 2018, suggesting a long‑standing presence that may have been repurposed for malicious use. VirusTotal scans have recorded 16 detections out of 91 security‑vendor submissions, demonstrating that a notable minority of AV engines flag the site as malicious.
Additionally, the domain is listed on a security blocklist and has been actively blocked by the PhishDestroy service, reinforcing the perception of ongoing abuse. No public evidence of SSL certificate details, HTTP response codes, Safe Browsing status, or Open Threat Exchange (OTX) entries is currently available, indicating that those vectors have not been publicly disclosed or have not yet been captured by monitoring platforms. The lack of a known page title or brand targeting further limits attribution, but the combination of IP hosting, Netlify registration, detection counts, and blocklist presence is consistent with a credential‑harvesting operation.
Uncertainty remains regarding the exact phishing campaign content, the specific victim population, and whether the site currently serves active malicious payloads. Defenders should continue to block the domain at network perimeters, update URL filtering rules to include the host, and monitor Netlify‑hosted IP ranges for similar patterns. Threat‑intel teams are advised to corroborate the domain’s activity with endpoint logs, capture any network traffic to the IP address, and consider sharing any newly observed indicators with community blocklists to improve collective defenses.
위협 대응 Pipeline
공개 차단 목록 상태
저장된 캡처
도메인 인텔리전스
기술적 세부 사항DNS, SSL SAN, 타임스탬프
사용 기술 · 2 identified
Netlify providers hosting and server-less backend services for web applications and static websites.
www.netlify.com 신뢰도 100%HTTP Strict Transport Security (HSTS) informs browsers that the site should only be accessed using HTTPS.
www.rfc-editor.org 신뢰도 100%VirusTotal 분석
사이트 성능 분석
Google PageSpeed Insights — mobile performance audit of cozy-tartufo-66895a.netlify.app · checked Jul 29, 2026
증거 및 외부 보고서
이 사이트로 인해 영향을 받으셨나요?
계정 자격 증명, 개인 정보 또는 결제 정보를 입력했거나 이 도메인에서 파일을 다운로드한 경우 즉시 조치를 취하세요. 다음은 사건을 신고하고 자신을 보호하는 데 도움이 되는 리소스입니다.
지역 당국에 신고하십시오
공식 사이버 범죄 연락처 또는 불만사항 초안 작성 →를 받으려면 국가를 선택하세요.