Analysis indicates that the domain storied-jelly-94f299.netlify.app is currently active and resolves to the IPv4 address 35.157.26.135. The domain is hosted on Netlify, as evidenced by the registration information stating "Registered through: Netlify" and the use of Netlify's shared hosting environment. The domain does not publish public nameserver records (NS_NOT_FOUND), which is consistent with Netlify's default DNS configuration that hides internal name server details. The infrastructure has been flagged by the PhishDestroy blocklist and is listed on one additional security blocklist, confirming that at least one security community has identified the site as malicious.
VirusTotal analysis shows that 11 of 91 scanning engines flagged the domain, indicating a moderate level of detection across anti‑malware and URL‑reputation services. The exact nature of the phishing payload is not yet disclosed; no page title, brand target, or lure type is available in the current intelligence set. Consequently, the specific credential‑stealing or account‑takeover vector remains uncertain. Defenders should treat the domain as high‑risk: it should be added to network‑level deny lists, DNS‑sinkhole rules, and browser security controls.
Continuous monitoring for changes in the page content, SSL certificate, or additional detections is recommended. Organizations using Netlify‑hosted services should verify that the domain is not part of legitimate internal deployments, as the shared hosting model can obscure the origin of malicious content. Blocking at the perimeter and educating users about unsolicited links to unknown Netlify subdomains can reduce exposure while further forensic analysis is conducted.