65b7d3757c56390008a2d84a--ods-android[.]netlify[.]app
“Getting started with Orange Design System for Android”
65b7d3757c56390008a2d84a--ods-android.netlify.app — Контент недоступен (HTTP 404). Олицетворение бренда: Orange; Тип мошенничества: Brand Impersonation. Сводка доказательств: VirusTotal 16/95 (ADMINUSLabs, Criminal IP, alphaMountain.ai, BitDefender, CyRadar); URLScan malicious verdict; Google Safe Browsing flagged; CF Radar malicious; PhishDestroy score 100/100. Регистратор: Netlify.
Подробный анализ PhishDestroy AI ниже оставлен на английском, чтобы сохранить исходную криминалистическую запись.
The domain 65b7d3757c56390008a2d84a--ods-android.netlify.app was taken offline prior to the report date of July 23, 2026, but historical analysis confirms it was actively used for a high‑risk Orange brand impersonation campaign. Infrastructure analysis shows the domain resolved to IP address 63.176.8.218, located in Germany and associated with ASN 16509 owned by Amazon.com, Inc. Authority for the DNS zone was provided by nsone.net servers (dns1.p04.nsone.net, dns2.p04.nsone.net). The site was hosted on Netlify, as indicated by the registration pathway, and employed HTTP Strict Transport Security (HSTS) with a DigiCert Global G2 TLS RSA SHA256 2020 CA1 certificate issued by DigiCert Inc. The page title retrieved from the site was "Getting started with Orange Design System for Android," directly referencing the targeted brand.
Google Safe Browsing flagged the domain for social engineering, and VirusTotal recorded 16 detections out of 95 scanned security vendors, reinforcing the malicious intent. Reputation services rated the site extremely poorly, with Scamadviser assigning a trust score of 1 out of 100, and PhishDestroy listed the domain on its blocklist. The site returned an HTTP 404 status, indicating that the original malicious content was no longer directly served at the time of observation, yet the combination of brand‑specific page title, security vendor detections, and blocklist inclusion confirms the domain’s role in a brand‑impersonation scheme.
Defenders should continue to block the domain at perimeter controls, monitor the associated IP range for any resurgence of similar activities, and update threat intelligence feeds with the observed indicators, including the domain name, IP address, SSL certificate fingerprint, and the identified page title. Ongoing vigilance is advised because the underlying Netlify hosting environment can be rapidly reprovisioned for new malicious sites targeting the same or other brands.
Сигналы безопасности
Данные сетевой безопасности
Процесс реагирования на угрозы
Статус в публичных блок-листах
Технологии · 3 identified
Netlify providers hosting and server-less backend services for web applications and static websites.
www.netlify.com 100% уверенностиHTTP Strict Transport Security (HSTS) informs browsers that the site should only be accessed using HTTPS.
www.rfc-editor.org 100% уверенностиАнализ VirusTotal
Архивные доказательства
Доказательства и внешние отчеты
Повлиял ли на вас этот сайт?
Если вы ввели учетные данные, личную или платежную информацию или загрузили файл с этого домена, примите немедленные меры. Ниже приведены ресурсы, которые помогут вам сообщить об инциденте и защитить себя.
Сообщите об этом в местные органы власти
Выберите свою страну, чтобы получить официальные контакты по киберпреступности или создать проект жалобы →.
Проверить любой домен
Анализ угроз с использованием сохраненного черного списка, WHOIS, DNS и общедоступных доказательств сканирования.
Сканировать сейчасСообщить о фишинге
Добавляйте подозрительные домены в нашу базу данных угроз — защищайте сообщество
СообщитьПоток оперативных данных об угрозах
Недавние сообщения о фишинге и наблюдаемые изменения доступности
ОтслеживатьБудьте в курсе событий, берегите себя
Отслеживайте актуальные угрозы или оспорьте эту запись, если считаете, что это ложное срабатывание