eloquent-churros-1fce9e[.]netlify[.]app
“Netflix India - Watch TV Shows Online, Watch Movies Online”
eloquent-churros-1fce9e.netlify.app — Контент недоступний. Уособлення бренду: Netflix; Тип шахрайства: Generic Phishing. Зведення доказів: VirusTotal 16/95 (ADMINUSLabs, Criminal IP, alphaMountain.ai, BitDefender, CyRadar); Google Safe Browsing flagged; CF Radar malicious; PhishDestroy score 100/100. Реєстратор: Netlify.
Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.
Analysis of the domain eloquent-churros-1fce9e.netlify.app, observed on July 23, 2026, indicates a high‑risk brand‑impersonation campaign targeting Netflix users. The site resolves to the IP address 18.208.88.157, which belongs to Amazon.com, Inc. (AS14618) and is located in the United States. The domain is hosted on Netlify, as evidenced by the registration information and the presence of Netlify‑specific technology signatures and HTTP Strict Transport Security (HSTS) headers. The TLS certificate presented is issued by DigiCert Global G2 TLS RSA SHA256 2020 CA1 and is valid for the Netlify subdomain, confirming the hosting provider’s involvement. The page title returned by the server is “Netflix India – Watch TV Shows Online, Watch Movies Online,” directly referencing the Netflix brand.
However, the HTTP response code is 404, indicating that the content is no longer accessible. VirusTotal records show that 16 of 95 scanned security vendors flag the domain, and Google Safe Browsing classifies it as a social‑engineering threat. The domain appears on a single security blocklist and has been added to the PhishDestroy blocklist. Nameserver queries resolve to dns1.p04.nsone.net and dns2.p04.nsone.net, consistent with Netlify’s DNS configuration. Reputation services assign a trust score of 1 out of 100 on Scamadviser, reflecting extreme malicious intent.
The limited detection count and single blocklist entry suggest that the campaign may have been short‑lived or rapidly taken down, as the current status is reported offline. No additional evidence such as screenshot captures or malware samples has been released, leaving the exact phishing payload unknown. Defenders should block the domain at network perimeter and update proxy and DNS filtering policies to include both the fully qualified domain name and its resolved IP address. Continuous monitoring of Netlify‑hosted subdomains for similar brand‑themed titles is advised, as the infrastructure can be rapidly provisioned.
Сигнали безпеки
Розвіддані з мережевої безпеки
Процес реагування на загрози Pipeline
Статус у публічних блоклистах
Технології · 2 identified
Netlify providers hosting and server-less backend services for web applications and static websites.
www.netlify.com 100% впевненостіHTTP Strict Transport Security (HSTS) informs browsers that the site should only be accessed using HTTPS.
www.rfc-editor.org 100% впевненостіАналіз VirusTotal
Архівні докази
Докази та зовнішні звіти
Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога