http://curious-gaufre-9397cd.netlify.app/HTTP 404
3.1 KB
1.4 KB
0 internal · 1 external
Content-Type: text/htmlServer: NetlifyAll stored response-header names (5)
Content-TypeDateServerX-Nf-Request-IdTransfer-Encoding“Log in to Roblox”
curious-gaufre-9397cd.netlify.app — 内容不可用. 品牌冒充:Roblox; 诈骗类型:Impersonation. 证据摘要: VirusTotal 14/91 (BitDefender, ESET, Emsisoft, Forcepoint ThreatSeeker, Fortinet); CF Radar malicious; PhishDestroy score 93/100. 注册商: Netlify.
为保留原始取证记录,下方的 PhishDestroy AI 详细分析仍使用英文。
This domain, curious-gaufre-9397cd.netlify.app, is actively flagged as a high-risk phishing site hosted on Netlify's infrastructure. Analysis reveals the domain is currently resolving to IP address 98.84.224.111 and remains operational as of July 28, 2026. The domain appears on two security blocklists, including PhishDestroy and OpenPhish, indicating confirmed malicious activity. VirusTotal reports 14 of 91 security vendors detecting the domain as malicious, providing further evidence of its fraudulent nature. Notably, the domain lacks configured nameservers, a common red flag in phishing infrastructure where attackers may exploit misconfigured or disposable hosting environments.
Infrastructure analysis shows the domain is registered through Netlify, a legitimate hosting provider often abused for rapid deployment of phishing pages. The absence of nameservers suggests the attackers may have used Netlify's platform to bypass traditional DNS checks or to quickly deploy disposable phishing pages. The IP address 98.84.224.111 does not provide additional attribution to a specific hosting provider or autonomous system at this time, but its association with active phishing activity warrants immediate blocking. Defenders should treat this domain as confirmed malicious and implement network-level blocks to prevent user access.
Given its presence on multiple blocklists and detection by security vendors, organizations are advised to update firewall rules, proxy filters, and endpoint protection systems to include this domain. No specific brand or scam type has been identified in the available data, so the exact nature of the phishing content remains unconfirmed. Further analysis of the page content is recommended to determine the targeted brand or credentials being harvested. Until such analysis is completed, the domain should be considered a generic phishing threat with high risk of credential theft or malware distribution.
AngularJS is a JavaScript-based open-source web application framework led by the Angular Team at Google.
angularjs.org 置信度 100%reCAPTCHA is a free service from Google that helps protect websites from spam and abuse.
www.google.com 置信度 100%Netlify providers hosting and server-less backend services for web applications and static websites.
www.netlify.com 置信度 100%HTTP Strict Transport Security (HSTS) informs browsers that the site should only be accessed using HTTPS.
www.rfc-editor.org 置信度 100%Google PageSpeed Insights — mobile performance audit of curious-gaufre-9397cd.netlify.app · checked Jul 28, 2026
Timestamped response metadata retained by the local collection pipeline. Each value below belongs to the displayed archive time.
http://curious-gaufre-9397cd.netlify.app/Content-Type: text/htmlServer: NetlifyContent-TypeDateServerX-Nf-Request-IdTransfer-Encoding如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。