netflix-clone-d9498[.]web[.]app
“Netflix Clone”
netflix-clone-d9498.web.app — Контент недоступен. Олицетворение бренда: Netflix; Тип мошенничества: Generic Phishing. Сводка доказательств: VirusTotal 15/95 (Criminal IP, alphaMountain.ai, BitDefender, CyRadar, Ermes); URLScan malicious verdict; CF Radar malicious; PhishDestroy score 95/100. Регистратор: Google Domains.
Подробный анализ PhishDestroy AI ниже оставлен на английском, чтобы сохранить исходную криминалистическую запись.
Analysis of the domain netflix-clone-d9498.web.app, observed on July 23, 2026, indicates that it was used for brand impersonation of Netflix. The site presented the page title “Netflix Clone”, directly referencing the target brand. The domain is hosted on Firebase infrastructure, confirmed by the presence of a Google‑issued TLS certificate (Google Trust Services / WR4) and the use of HTTP/3 with HSTS enabled. DNS resolution points to IP address 199.36.158.100, which belongs to AS54113 Fastly, Inc., a content‑delivery network commonly leveraged by Firebase‑based deployments. The registrar record shows the domain was registered through Google LLC, consistent with the Firebase hosting environment.
VirusTotal scans have recorded 15 detections out of 95 security vendors, indicating that multiple anti‑malware engines flag the domain as malicious. The domain appears on one public blocklist and is specifically listed by PhishDestroy, confirming that at least one dedicated anti‑phishing service has taken it down. Current HTTP response is 404, and the domain status is marked offline, suggesting the malicious content has been removed or the site is no longer serving pages. Nameserver information is unavailable (NS_NOT_FOUND), limiting further DNS‑level attribution. No additional threat intelligence sources such as OTX or Safe Browsing entries were provided.
Consequently, while the available evidence strongly supports a brand‑impersonation campaign targeting Netflix users, the exact content and tactics employed on the site cannot be verified because the site is offline. Defenders should continue to block the domain at perimeter and endpoint controls, monitor for any re‑registration attempts, and add the IP address 199.36.158.100 to watchlists, bearing in mind that the address is part of a shared CDN and may host legitimate services.
Данные сетевой безопасности
Процесс реагирования на угрозы
Статус в публичных блок-листах
Сохранённый снимок
Аналитика доменов
Технические сведенияDNS, SAN в протоколе SSL, временные метки
Технологии · 3 identified
Google platform for building mobile and web applications with backend services.
HTTP Strict Transport Security — forces browsers to use HTTPS connections only.
Third major version of HTTP protocol, built on QUIC for faster, more reliable connections.
Анализ VirusTotal
Архивные доказательства
Доказательства и внешние отчеты
Повлиял ли на вас этот сайт?
Если вы ввели учетные данные, личную или платежную информацию или загрузили файл с этого домена, примите немедленные меры. Ниже приведены ресурсы, которые помогут вам сообщить об инциденте и защитить себя.
Сообщите об этом в местные органы власти
Выберите свою страну, чтобы получить официальные контакты по киберпреступности или создать проект жалобы →.
Проверить любой домен
Анализ угроз с использованием сохраненного черного списка, WHOIS, DNS и общедоступных доказательств сканирования.
Сканировать сейчасСообщить о фишинге
Добавляйте подозрительные домены в нашу базу данных угроз — защищайте сообщество
СообщитьПоток оперативных данных об угрозах
Недавние сообщения о фишинге и наблюдаемые изменения доступности
ОтслеживатьБудьте в курсе событий, берегите себя
Отслеживайте актуальные угрозы или оспорьте эту запись, если считаете, что это ложное срабатывание