netflix-clone-eight-blond[.]vercel[.]app
“Clone of Netflix”
netflix-clone-eight-blond.vercel.app — 内容不可用. 品牌冒充:Apple; 诈骗类型:Tech Support Scam. 证据摘要: VirusTotal 21/94 (ADMINUSLabs, Criminal IP, BitDefender, CyRadar, ESET); URLQuery 4 alerts; Google Safe Browsing flagged; CF Radar malicious; PhishDestroy score 100/100. 注册商: Vercel.
为保留原始取证记录,下方的 PhishDestroy AI 详细分析仍使用英文。
This domain netflix-clone-eight-blond.vercel.app is assessed as a high-risk brand impersonation infrastructure designed to deceive users by mimicking legitimate services while targeting Apple brand trust. The observed configuration indicates a credential phishing intent, where users may be lured into entering sensitive account information through a deceptive interface presented as a legitimate platform. Despite the misleading page title referencing a different service, threat intelligence indicates Apple impersonation as the primary targeting vector, suggesting cross-brand baiting to increase victim engagement and reduce suspicion. Such domains are typically used in staged phishing campaigns, where initial landing pages establish trust before redirecting or harvesting credentials.
This infrastructure is supported by multiple detection signals: VirusTotal classification shows 21/95 security vendors flagging the domain. The domain was registered through Vercel Inc. and created on March 08, 2026. It currently appears on 1 security blocklist, indicating active monitoring and confirmed malicious behavior. Network resolution points to IP address 216.198.79.67, hosted under US-based AS16509 Amazon.com, Inc. The SSL certificate is issued by Google Trust Services under WR1 profile, suggesting automated certificate provisioning common in rapidly deployed phishing infrastructure. These combined indicators show a recently created, actively hosted environment with cross-provider infrastructure usage typical of scalable phishing operations.
If a user has visited or interacted with this domain, immediate risk mitigation is required. Users should avoid entering any credentials or personal data and should assume any information submitted may be compromised. Passwords reused across other services should be changed immediately, and multi-factor authentication should be enabled where possible. Endpoint scans should be performed to detect potential malware or persistence mechanisms. Additionally, network-level monitoring for unusual login attempts or unauthorized access should be reviewed. Organizations should block the domain at DNS, proxy, and endpoint layers and add the indicators (domain, IP 216.198.79.67) to threat intelligence feeds. Given the active status of the infrastructure, continued monitoring is recommended to detect potential domain rotation or related impersonation clusters.
网络安全情报
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| Cloudflare DNS | netflix-clone-eight-blond.vercel.app |
malicious | Sinkholed |
| OpenDNS | netflix-clone-eight-blond.vercel.app |
phishing | Phishing Block |
| Quad9 DNS | netflix-clone-eight-blond.vercel.app |
malicious | Sinkholed |
| DNS4EU | netflix-clone-eight-blond.vercel.app |
malicious | Sinkholed |
威胁响应 Pipeline
公共封禁名单状态
所用技术 · 2 identified
HTTP Strict Transport Security (HSTS) informs browsers that the site should only be accessed using HTTPS.
www.rfc-editor.org 置信度 100%VirusTotal 分析
存档证据
网站性能分析
Google PageSpeed Insights — mobile performance audit of netflix-clone-eight-blond.vercel.app · checked Mar 10, 2026
证据与外部报告
您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。