account-membership[.]vercel[.]app
“Netflix - Watch TV Shows Online, Watch Movies Online”
account-membership.vercel.app — Неперевірений. Уособлення бренду: Netflix; Тип шахрайства: Credential Phishing. Зведення доказів: VirusTotal 20/91 (Criminal IP, alphaMountain.ai, BitDefender, CyRadar, Ermes); CF Radar malicious; PhishDestroy score 95/100. Реєстратор: Vercel.
Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.
This domain, account-membership.vercel.app, is actively impersonating Netflix as part of a credential phishing campaign. Registered on June 25, 2026, through Vercel Inc., it resolves to 64.29.17.195 (AS16509, United States) and currently returns an HTTP 200 status. The page title explicitly mimics Netflix branding ('Netflix - Watch TV Shows Online, Watch Movies Online'), aligning with the credential phishing classification. Infrastructure analysis reveals Vercel hosting, jsDelivr CDN usage, and HSTS implementation, alongside a Google Trust Services SSL certificate (WR1). Nameservers are unresolvable, a potential indicator of ephemeral or misconfigured infrastructure. Security vendors have flagged the domain, with 16 of 91 detections on record, and it appears on at least one blocklist. The domain remains operational as of July 12, 2026, with no evidence of takedown. Defenders should prioritize blocking or monitoring this domain, particularly in environments where Netflix credentials are sensitive. While the exact phishing kit or backend infrastructure is not analyzed, the combination of brand impersonation, credential-harvesting intent, and Vercel hosting is consistent with high-risk phishing operations. No additional context about the threat actor or campaign linkages is available at this time.
Розвіддані з мережевої безпеки
Процес реагування на загрози Pipeline
Статус у публічних блоклистах
Технології · 3 identified
Vercel is a cloud platform for static frontends and serverless functions.
vercel.com 100% впевненостіJSDelivr is a free public CDN for open-source projects. It can serve web files directly from the npm registry and GitHub repositories without any configuration.
www.jsdelivr.com 100% впевненостіHTTP Strict Transport Security (HSTS) informs browsers that the site should only be accessed using HTTPS.
www.rfc-editor.org 100% впевненостіАналіз VirusTotal
Докази та зовнішні звіти
Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога