belbuilnet[.]netlify[.]app
“Bell”
belbuilnet.netlify.app — 内容不可用. 品牌冒充:Bcebell; 诈骗类型:Credential Phishing. 证据摘要: VirusTotal 20/91 (Criminal IP, alphaMountain.ai, BitDefender, CyRadar, ESET); URLScan malicious verdict; CF Radar malicious; PhishDestroy score 95/100. 注册商: Netlify.
为保留原始取证记录,下方的 PhishDestroy AI 详细分析仍使用英文。
This domain operates as a high-risk phishing page designed to impersonate a legitimate “Bell” login or brand interface. Analysis indicates a credential-harvesting setup built to trick users into entering sensitive authentication data on a fraudulent portal. The infrastructure is consistent with generic phishing campaigns focused on account takeover and identity theft.
Infrastructure analysis shows belbuilnet.netlify.app is hosted via Netlify and resolves to IP 35.157.26.135 located in DE under AS16509 Amazon.com, Inc. The site uses a DigiCert Inc / DigiCert Global G2 TLS RSA SHA256 2020 CA1 SSL certificate. The domain remains active and is listed on 1 security blocklist (PhishDestroy). VirusTotal telemetry reports 20/95 security vendors flagging the domain as malicious. The page title is “Bell”, indicating likely brand impersonation to increase user trust and click-through rates.
If a user has interacted with this domain, it should be treated as a potential credential compromise event. Immediate mitigation includes changing any passwords potentially entered on the site, prioritizing email and financial accounts. Session tokens should be revoked across affected services, and multi-factor authentication should be enabled or reviewed. A full device malware scan is recommended to rule out secondary payload delivery. Users should also monitor accounts for unauthorized access, suspicious login attempts, or financial anomalies. Any reused passwords across services should be replaced to prevent lateral account compromise. Continued vigilance is necessary due to the active status of the infrastructure and ongoing detection by multiple security vendors.
网络安全情报
威胁响应 Pipeline
公共封禁名单状态
所用技术 · 2 identified
Netlify providers hosting and server-less backend services for web applications and static websites.
www.netlify.com 置信度 100%HTTP Strict Transport Security (HSTS) informs browsers that the site should only be accessed using HTTPS.
www.rfc-editor.org 置信度 100%VirusTotal 分析
证据与外部报告
您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。