http://phenomenal-florentine-a79a22.netlify.app/HTTP 503
3.3 KB
1.2 KB
0 internal · 1 external
Content-Type: text/htmlServer: NetlifyAll stored response-header names (5)
Content-TypeDateServerX-Nf-Request-IdTransfer-Encoding“Roblox — вход”
phenomenal-florentine-a79a22.netlify.app — Контент недоступен. Олицетворение бренда: Roblox; Тип мошенничества: Impersonation. Сводка доказательств: VirusTotal 16/91 (BitDefender, ESET, Emsisoft, Forcepoint ThreatSeeker, Fortinet); Google Safe Browsing flagged; CF Radar malicious; PhishDestroy score 100/100. Регистратор: Netlify.
Подробный анализ PhishDestroy AI ниже оставлен на английском, чтобы сохранить исходную криминалистическую запись.
Analysis indicates that the domain phenomenal-florentine-a79a22.netlify.app is actively being used for a generic phishing campaign and is classified as high risk. Google Safe Browsing has flagged the site for social engineering, confirming that the URL is associated with deceptive practices intended to harvest credentials or personal information. The domain resolves to the IP address 63.176.8.218, which is hosted by Netlify, as evidenced by the registration information that lists Netlify as the registrar.
Infrastructure inspection shows that the domain’s nameserver records are unavailable (NS_NOT_FOUND), which may hinder rapid DNS‑based mitigation but does not affect the observed malicious activity. The domain appears on two reputable phishing blocklists—PhishDestroy and OpenPhish—demonstrating that multiple independent threat intelligence sources have identified and shared its malicious nature. VirusTotal analysis reports that 16 of 91 security vendors have flagged the domain, providing additional corroboration of its malicious status.
The current operational status is listed as active, indicating that the phishing infrastructure remains online and capable of targeting users. Defenders should immediately block network traffic to both the domain and its resolved IP address, update URL filtering policies to include the domain, and ensure that endpoint protection solutions are configured to recognize the associated Safe Browsing and blocklist indicators. Continuous monitoring of Netlify‑hosted assets and periodic re‑evaluation of the domain’s reputation are advised, given the dynamic nature of phishing campaigns.
Netlify providers hosting and server-less backend services for web applications and static websites.
www.netlify.com 100% уверенностиHTTP Strict Transport Security (HSTS) informs browsers that the site should only be accessed using HTTPS.
www.rfc-editor.org 100% уверенностиGoogle PageSpeed Insights — mobile performance audit of phenomenal-florentine-a79a22.netlify.app · checked Jul 28, 2026
Timestamped response metadata retained by the local collection pipeline. Each value below belongs to the displayed archive time.
http://phenomenal-florentine-a79a22.netlify.app/Content-Type: text/htmlServer: NetlifyContent-TypeDateServerX-Nf-Request-IdTransfer-EncodingЕсли вы ввели учетные данные, личную или платежную информацию или загрузили файл с этого домена, примите немедленные меры. Ниже приведены ресурсы, которые помогут вам сообщить об инциденте и защитить себя.
Выберите свою страну, чтобы получить официальные контакты по киберпреступности или создать проект жалобы →.
Анализ угроз с использованием сохраненного черного списка, WHOIS, DNS и общедоступных доказательств сканирования.
Сканировать сейчасДобавляйте подозрительные домены в нашу базу данных угроз — защищайте сообщество
СообщитьНедавние сообщения о фишинге и наблюдаемые изменения доступности
ОтслеживатьОтслеживайте актуальные угрозы или оспорьте эту запись, если считаете, что это ложное срабатывание