netflix-clone-nine-sand[.]vercel[.]app
“Netflix”
netflix-clone-nine-sand.vercel.app — Прикритий · доступний. Уособлення бренду: Netflix; Тип шахрайства: Generic Phishing. Зведення доказів: VirusTotal 25/94 (ADMINUSLabs, Criminal IP, alphaMountain.ai, BitDefender, Certego); Google Safe Browsing flagged; CF Radar malicious; cloaking observed; PhishDestroy score 100/100. Реєстратор: Vercel.
Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.
PhishDestroy identifies netflix-clone-nine-sand.vercel.app as a high-risk credential-harvesting domain masquerading as a Netflix clone. This site employs social engineering tactics to trick users into surrendering credentials under the guise of account verification or payment processing. No evidence suggests the use of a drainer kit, but the domain’s rapid deployment and obfuscated path (nine-sand) indicate an opportunistic campaign targeting streaming service users. The threat actor leverages Vercel’s hosting infrastructure to lend superficial legitimacy to the phishing page, exploiting free-tier deployments to evade traditional takedown mechanisms.
Technical indicators confirm the domain’s malicious intent: VirusTotal flags this domain with a score of 21/95 security vendors, while Google Safe Browsing classifies it under SOCIAL_ENGINEERING. Registered through Vercel Inc., the domain resolves to IP 64.29.17.3 and has been observed on a single security blocklist. Notably, OpenPhish has already blacklisted this domain, underscoring its active threat status. The SSL certificate, issued by Google Trust Services, may further deceive users into trusting the fraudulent site.
This domain remains active as of the latest assessment, with immediate takedown efforts complicated by Vercel’s hosting policies and the domain’s rapid evasion tactics. Users are strongly advised to avoid interacting with this site and report it through their browser’s built-in safety tools. While current blocklists mitigate exposure, the risk persists due to the threat actor’s potential to re-deploy under new subdomains or variations. Organizations should update firewall rules to block IP 64.29.17.3 and propagate the IOCs to threat intelligence platforms to prevent downstream compromise.
Розвіддані з мережевої безпеки
Процес реагування на загрози Pipeline
Статус у публічних блоклистах
Криміналістичні дані
Технології · 3 identified
Popular CSS framework for responsive, mobile-first web development.
Cloud platform for frontend deployment, optimized for Next.js.
HTTP Strict Transport Security — forces browsers to use HTTPS connections only.
Аналіз VirusTotal
Аналіз продуктивності сайту
Google PageSpeed Insights — mobile performance audit of netflix-clone-nine-sand.vercel.app · checked Mar 31, 2026
Докази та зовнішні звіти
Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога