netflix-clone-nine-sand[.]vercel[.]app
“Netflix”
netflix-clone-nine-sand.vercel.app — Gizlenmiş · ulaşılabilir. Marka kimliğine bürünme: Netflix; Dolandırıcılık türü: Generic Phishing. Kanıt özeti: VirusTotal 25/94 (ADMINUSLabs, Criminal IP, alphaMountain.ai, BitDefender, Certego); Google Safe Browsing flagged; CF Radar malicious; cloaking observed; PhishDestroy score 100/100. Kayıt kuruluşu: Vercel.
Özgün adli kaydı korumak için aşağıdaki ayrıntılı PhishDestroy AI analizi İngilizce bırakılmıştır.
PhishDestroy identifies netflix-clone-nine-sand.vercel.app as a high-risk credential-harvesting domain masquerading as a Netflix clone. This site employs social engineering tactics to trick users into surrendering credentials under the guise of account verification or payment processing. No evidence suggests the use of a drainer kit, but the domain’s rapid deployment and obfuscated path (nine-sand) indicate an opportunistic campaign targeting streaming service users. The threat actor leverages Vercel’s hosting infrastructure to lend superficial legitimacy to the phishing page, exploiting free-tier deployments to evade traditional takedown mechanisms.
Technical indicators confirm the domain’s malicious intent: VirusTotal flags this domain with a score of 21/95 security vendors, while Google Safe Browsing classifies it under SOCIAL_ENGINEERING. Registered through Vercel Inc., the domain resolves to IP 64.29.17.3 and has been observed on a single security blocklist. Notably, OpenPhish has already blacklisted this domain, underscoring its active threat status. The SSL certificate, issued by Google Trust Services, may further deceive users into trusting the fraudulent site.
This domain remains active as of the latest assessment, with immediate takedown efforts complicated by Vercel’s hosting policies and the domain’s rapid evasion tactics. Users are strongly advised to avoid interacting with this site and report it through their browser’s built-in safety tools. While current blocklists mitigate exposure, the risk persists due to the threat actor’s potential to re-deploy under new subdomains or variations. Organizations should update firewall rules to block IP 64.29.17.3 and propagate the IOCs to threat intelligence platforms to prevent downstream compromise.
Ağ Güvenliği İstihbaratı
Tehdit Müdahale Pipeline
Genel Engelleme Listesi Durumu
Adli İstihbarat
Teknolojiler · 3 identified
Popular CSS framework for responsive, mobile-first web development.
Cloud platform for frontend deployment, optimized for Next.js.
HTTP Strict Transport Security — forces browsers to use HTTPS connections only.
VirusTotal Analizi
Site Performans Analizi
Google PageSpeed Insights — mobile performance audit of netflix-clone-nine-sand.vercel.app · checked Mar 31, 2026
Kanıtlar ve Dış Raporlar
Bu Siteden Etkilendiniz mi?
Hesap kimlik bilgilerini, kişisel bilgileri veya ödeme bilgilerini girdiyseniz ya da bu alan adından bir dosya indirdiyseniz hemen harekete geçin. Aşağıda olayı bildirmenize ve kendinizi korumanıza yardımcı olacak kaynaklar bulunmaktadır.
Yerel Yetkililere Bildirin
resmi siber suç iletişim bilgileri veya şikayet taslağı oluştur → almak için ülkenizi seçin.
Herhangi Bir Alan Adını Kontrol Et
Saklanan engelleme listesi, WHOIS, DNS ve genel tarama kanıtlarını kullanarak tehdit analizi
Şimdi TaraOltalama Olayını Bildir
Şüpheli alan adlarını tehdit veritabanımıza bildirin — topluluğu koruyun
BildirCanlı Tehdit Akışı
Son kimlik avı raporları ve gözlemlenen kullanılabilirlik değişiklikleri
İzleGelişmelerden Haberdar Olun, Güvende Kalın
Canlı tehditleri izleyin veya bunun yanlış bir uyarı olduğunu düşünüyorsanız bu kayda itiraz edin