http://stellar-sherbet-1b477b.netlify.app/HTTP 503
3.3 KB
1.2 KB
0 internal · 1 external
Content-Type: text/htmlServer: NetlifyAll stored response-header names (5)
Content-TypeDateServerX-Nf-Request-IdTransfer-Encoding“Log in to Roblox”
stellar-sherbet-1b477b.netlify.app — Контент недоступен. Олицетворение бренда: Roblox; Тип мошенничества: Impersonation. Сводка доказательств: VirusTotal 11/91 (alphaMountain.ai, BitDefender, ESET, Emsisoft, Fortinet); Google Safe Browsing flagged; CF Radar malicious; PhishDestroy score 83/100. Регистратор: Netlify.
Подробный анализ PhishDestroy AI ниже оставлен на английском, чтобы сохранить исходную криминалистическую запись.
The domain stellar-sherbet-1b477b.netlify.app is currently active and was provisioned through the Netlify hosting platform. DNS resolution points exclusively to the IPv4 address 63.176.8.218, which is the sole host associated with this domain in the available intelligence. Netlify’s default nameserver configuration is not disclosed; the known nameserver field returns NS_NOT_FOUND, indicating that conventional NS lookups did not return a custom set of authoritative servers. VirusTotal analysis shows that 11 of 91 security vendors have flagged the domain, reflecting a moderate level of detection across independent scanning engines.
Google Safe Browsing classifies the site as a social engineering threat, confirming that automated web‑risk services consider the URL to be malicious. The domain is listed on at least one external security blocklist and has been actively blocked by the PhishDestroy mitigation service, providing further evidence of its abusive purpose. No public information is available regarding SSL/TLS certificate details, HTTP response codes, page title, or any associated evidence links, leaving those aspects of the site’s surface unverified. The combination of Netlify hosting, a single IP endpoint, and multiple vendor detections suggests a deliberately deployed phishing infrastructure rather than an incidental compromise.
Defenders should prioritize blocking outbound connections to 63.176.8.218 at the network perimeter and add stellar-sherbet-1b477b.netlify.app to local and cloud‑based URL filtering rules. Continuous monitoring of Netlify‑hosted domains for similar detection patterns is advisable, as the provider’s shared infrastructure can be leveraged for rapid deployment of additional malicious sites. Organizations should also incorporate threat‑intel feeds that reference the 11 vendor detections and Google Safe Browsing flag into their security orchestration pipelines to ensure timely response to any future activity originating from this domain.
AngularJS is a JavaScript-based open-source web application framework led by the Angular Team at Google.
angularjs.org 100% уверенностиNetlify providers hosting and server-less backend services for web applications and static websites.
www.netlify.com 100% уверенностиHTTP Strict Transport Security (HSTS) informs browsers that the site should only be accessed using HTTPS.
www.rfc-editor.org 100% уверенностиGoogle PageSpeed Insights — mobile performance audit of stellar-sherbet-1b477b.netlify.app · checked Jul 28, 2026
Timestamped response metadata retained by the local collection pipeline. Each value below belongs to the displayed archive time.
http://stellar-sherbet-1b477b.netlify.app/Content-Type: text/htmlServer: NetlifyContent-TypeDateServerX-Nf-Request-IdTransfer-EncodingЕсли вы ввели учетные данные, личную или платежную информацию или загрузили файл с этого домена, примите немедленные меры. Ниже приведены ресурсы, которые помогут вам сообщить об инциденте и защитить себя.
Выберите свою страну, чтобы получить официальные контакты по киберпреступности или создать проект жалобы →.
Анализ угроз с использованием сохраненного черного списка, WHOIS, DNS и общедоступных доказательств сканирования.
Сканировать сейчасДобавляйте подозрительные домены в нашу базу данных угроз — защищайте сообщество
СообщитьНедавние сообщения о фишинге и наблюдаемые изменения доступности
ОтслеживатьОтслеживайте актуальные угрозы или оспорьте эту запись, если считаете, что это ложное срабатывание