The domain netfliclonebyrohit.netlify.app is currently active and has been identified as a high‑risk credential‑theft operation. Google Safe Browsing has flagged the site for social engineering, indicating that it is likely employed to lure users into revealing personal data. Independent threat‑intelligence feeds have corroborated this assessment: PhishDestroy lists the domain as blocked, and one public security blocklist also contains it. The domain resolves to the IP address 35.157.26.135, which belongs to Netlify’s hosting infrastructure; Netlify is also recorded as the registrar, confirming that the site is hosted on a legitimate cloud‑service platform often abused by malicious actors.
VirusTotal analysis shows that 14 of 91 scanned security vendors have flagged the domain, providing additional evidence of malicious behavior. Nameserver information is unavailable, which limits visibility into the domain’s DNS configuration. No further technical details such as SSL certificate attributes, HTTP response codes, or page titles have been published, leaving the exact content and lure technique unverified. Defenders should prioritize the immediate addition of netfliclonebyrohit.netlify.app to URL filtering, DNS sink‑hole, and endpoint protection rules.
Network monitoring should include the associated IP 35.157.26.135 to detect any outbound connections originating from internal assets. Continuous re‑evaluation of the domain’s status is advised, as threat actors frequently shift hosting or employ fast‑flux techniques. Organizations are encouraged to share any observed traffic or infection indicators with upstream blocklist providers to improve collective detection coverage.