eng-metmskks-web[.]netlify[.]app
“Site not found”
eng-metmskks-web.netlify.app — 콘텐츠를 사용할 수 없음. 증거 요약: VirusTotal 14/95 (ADMINUSLabs, ChainPatrol, alphaMountain.ai, BitDefender, CRDF); Google Safe Browsing flagged; PhishDestroy score 92/100. 등록기관: Netlify.
원본 포렌식 기록을 보존하기 위해 아래의 상세 PhishDestroy AI 분석은 영어로 유지됩니다.
The domain eng-metmskks-web.netlify.app was observed hosting a generic phishing page that returned a 404 response with the title “Site not found”. DNS resolution points to the IPv4 address 98.84.224.111, which is allocated to Amazon.com, Inc. (AS14618) and geolocated to the United States. The site was deployed on Netlify, as indicated by the Netlify technology fingerprint and the presence of HTTP Strict Transport Security (HSTS) headers. The TLS certificate presented by the host is issued by DigiCert Global G2 TLS RSA SHA256 2020 CA1 and is signed by DigiCert Inc., confirming the use of a valid public‑trusted certificate chain.
Google Safe Browsing classifies the domain as “social engineering”, and the domain appears on a single security blocklist that has already taken it offline. It is also listed by the PhishDestroy blocklist, confirming that active mitigation has been applied. VirusTotal scans show that 14 of 95 antivirus and URL‑reputation engines flagged the domain, reinforcing the malicious assessment. Registrar information shows the site was created through Netlify’s hosting service; the nameserver query returned NS_NOT_FOUND, indicating that standard authoritative name servers are not exposed.
The HTTP status code 404 and the “Site not found” page title suggest that the malicious content has been removed or the site has been deliberately taken down. Given the combination of a known phishing classification, a malicious blocklist presence, multiple vendor detections, and the use of a reputable TLS certificate to lend credibility, defenders should continue to block the domain at network perimeters and endpoint filters. Monitoring of the associated IP address 98.84.224.111 for any resurgence of malicious activity is advisable, as the hosting provider may be reused for future campaigns. Incident response teams should also update any URL reputation feeds with the current findings to ensure rapid detection of repeat attempts.
위협 대응 Pipeline
공개 차단 목록 상태
사용 기술 · 2 identified
Netlify providers hosting and server-less backend services for web applications and static websites.
www.netlify.com 신뢰도 100%HTTP Strict Transport Security (HSTS) informs browsers that the site should only be accessed using HTTPS.
www.rfc-editor.org 신뢰도 100%VirusTotal 분석
보관된 증거
증거 및 외부 보고서
이 사이트로 인해 영향을 받으셨나요?
계정 자격 증명, 개인 정보 또는 결제 정보를 입력했거나 이 도메인에서 파일을 다운로드한 경우 즉시 조치를 취하세요. 다음은 사건을 신고하고 자신을 보호하는 데 도움이 되는 리소스입니다.
지역 당국에 신고하십시오
공식 사이버 범죄 연락처 또는 불만사항 초안 작성 →를 받으려면 국가를 선택하세요.