singular-lollipop-73afd5[.]netlify[.]app
“Netflix Clone”
singular-lollipop-73afd5.netlify.app — Контент недоступний. Уособлення бренду: Netflix; Тип шахрайства: Generic Phishing. Зведення доказів: VirusTotal 17/95 (Criminal IP, alphaMountain.ai, BitDefender, CRDF, CyRadar); URLScan malicious verdict; CF Radar malicious; PhishDestroy score 95/100. Реєстратор: Netlify.
Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.
This domain, singular-lollipop-73afd5.netlify.app, is flagged as a brand impersonation threat targeting Netflix. Analysis indicates the page title explicitly labels it as a 'Netflix Clone,' suggesting an intent to deceive users into believing they are interacting with legitimate Netflix infrastructure. The domain was hosted on a content delivery platform and did not employ a custom domain, increasing its likelihood of being part of a larger, disposable phishing campaign designed to harvest streaming service credentials or payment information. Infrastructure analysis reveals the following technical indicators: the domain is detected by 17 out of 95 security vendors on a malware analysis platform, indicating moderate consensus on its malicious nature. It was registered through a platform-as-a-service provider and resolved to the IP address 98.84.224.111, geolocated within the United States under autonomous system AS14618. The SSL certificate, issued by a widely trusted certificate authority, was valid and did not exhibit anomalies, though this is common in phishing domains to avoid immediate browser warnings. The domain appeared on two security blocklists, including community-driven repositories tracking active phishing threats. As of the latest verification, singular-lollipop-73afd5.netlify.app has been taken offline, likely following abuse reports or automated takedown procedures. However, the infrastructure used—particularly the hosting provider and content delivery network—remains operational and may be reused for similar campaigns. Users who accessed the domain prior to its removal should assume credential exposure and initiate password resets on their Netflix accounts, along with reviewing linked payment methods for unauthorized activity. Organizations should monitor for related domains leveraging the same hosting pattern or impersonating other streaming services, as this campaign may represent a broader trend in credential harvesting operations.
Розвіддані з мережевої безпеки
Процес реагування на загрози Pipeline
Статус у публічних блоклистах
Технології · 2 identified
Netlify providers hosting and server-less backend services for web applications and static websites.
www.netlify.com 100% впевненостіHTTP Strict Transport Security (HSTS) informs browsers that the site should only be accessed using HTTPS.
www.rfc-editor.org 100% впевненостіАналіз VirusTotal
Архівні докази
Докази та зовнішні звіти
Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога