Analysis of votelistingstatus-cc.netlify.app as of July 29, 2026 indicates that the domain is actively used for a generic phishing campaign. The domain resolves to the IPv4 address 35.157.26.135, an address associated with Netlify's hosting infrastructure. Registration details show the site was provisioned through Netlify, and the authoritative name server information is unavailable (NS_NOT_FOUND). The domain has been added to a single security blocklist and is currently listed as blocked by the PhishDestroy service, confirming that at least one threat intelligence feed has identified malicious activity linked to this host.
VirusTotal reports that the domain was scanned by 91 antivirus and URL analysis engines; none of those engines returned a detection at the time of the scan. While the lack of detections might suggest a low false‑positive rate, it does not constitute evidence of safety, as many phishing sites evade signature‑based detection. No public Safe Browsing, Open Threat Exchange, SSL certificate, HTTP status, or page title information is available for this domain, leaving those vectors unverified. Given the confirmed hosting on a popular static‑site platform, the presence on a blocklist, and the active phishing classification by PhishDestroy, defenders should treat the domain as malicious.
Recommended actions include adding the domain to local deny lists, monitoring DNS queries for the 35.157.26.135 address, and continuing to observe threat‑intel feeds for any changes in detection status. Organizations should also consider employing URL filtering solutions that reference the known blocklist entry to prevent user access to the site. The current evidence does not provide details on the specific phishing lure or target brand, so further investigation of the payload would be required to fully characterize the campaign.