Analysis of eventchecker-wg.netlify.app indicates that the site is hosted on Netlify infrastructure and remains active as of the report date, July 30, 2026. The domain resolves to the IP address 35.157.26.135, which is owned by Netlify and commonly used for a variety of client sites. DNS queries return no nameserver information (NS_NOT_FOUND), suggesting that the domain relies on Netlify’s default DNS handling.
The domain has been observed on three external security blocklists and is explicitly blocked by PhishDestroy, MetaMask, and the SEAL project, reinforcing a high‑risk assessment despite the absence of detections from the 91 VirusTotal scanners that have examined the site. No public page title, brand target, or specific phishing kit information is currently available, so the exact content and impersonated entity cannot be confirmed. Defenders should treat the domain as a malicious phishing vector and add it to network‑level deny lists, proxy filters, and endpoint protection rules.
Continuous monitoring of DNS and HTTP activity toward the IP 35.157.26.135 is advised, as Netlify hosts many unrelated legitimate sites and the malicious payload could be switched without altering the IP. Organizations should also enforce strict user awareness training to reduce the likelihood of credential harvesting attempts originating from this domain.