This domain ntfclon.netlify.app is currently flagged as a high‑risk generic phishing infrastructure. VirusTotal reports that 11 of 91 security vendors have identified malicious activity associated with the host, indicating a non‑trivial detection rate. The domain is listed on a single external blocklist and is actively blocked by the PhishDestroy service, confirming that at least one dedicated anti‑phishing platform has taken mitigation steps.
Registration information shows the site was provisioned through Netlify, a popular static‑site hosting provider, and the public DNS records do not reveal custom nameservers, returning NS_NOT_FOUND. The hostname resolves to the IPv4 address 63.176.8.218, which is the sole resolved endpoint observed in network scans. No additional intelligence such as SSL certificate details, HTTP response codes, page title, or brand targeting has been published, leaving the exact content of the page unverified.
Consequently, while the available indicators confirm malicious intent, the lack of visible page metadata limits the ability to attribute a specific phishing campaign or victim set. Defenders should add ntfclon.netlify.app to domain blocklists, enforce outbound filtering for the resolved IP address, and monitor Netlify‑hosted subdomains for similar patterns. Continuous re‑evaluation is recommended, as the active status and observed vendor detections suggest the infrastructure may evolve or be repurposed.