deepak2006ez-ship-it[.]github[.]io
“Netflix clone”
Збережене спостереження
Зафіксована відмінність заголовків
Зведення доказів
This domain is flagged as a high-risk credential harvesting phishing site specifically impersonating Netflix login portals. Analysis indicates the infrastructure is designed to deceive users into submitting account credentials, payment details, or personal information under the guise of a legitimate streaming service interface. The threat type is classified as a brand impersonation phishing attack targeting Netflix users. Infrastructure analysis reveals the domain deepak2006ez-ship-it.github.io is hosted on GitHub Pages, resolving to IP address 185.199.109.153 within AS54113 (Fastly, Inc.), located in the United States. The SSL certificate is issued by Let's Encrypt (YR2), a common choice for both legitimate and malicious sites. Security vendor detection on VirusTotal stands at 8 out of 95 engines, while Google Safe Browsing explicitly flags the domain as phishing. The page title explicitly states 'Netflix clone,' confirming the impersonation intent. The domain appears on one security blocklist and is actively blocked by PhishDestroy. Registration details indicate the domain was created through GitHub, Inc., leveraging a free hosting service to evade traditional domain registration scrutiny. Mitigation steps for this specific threat type include immediate blocking of the domain and associated IP address at network perimeter controls. Security teams should prioritize alerting users about Netflix-themed phishing attempts, emphasizing verification of the URL and SSL certificate issuer before entering credentials. Organizations should monitor for credential submissions to this domain in web proxy logs and implement multi-factor authentication to reduce the impact of potential credential theft. End users should be trained to recognize cloned login pages, particularly those hosted on GitHub Pages or other free hosting services, and to report suspicious activity to their security teams. Given the active status of this domain, continuous monitoring for related infrastructure or similar impersonation attempts is recommended.
Data Coverage
Процес реагування на загрози Pipeline
Перевірка за блок-листами
10 зовнішніх джерел під наглядом · знімок від 11.08.2026
Технології
Виявлено 3 технології з високою впевненістю
Аналіз VirusTotal
Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога