netflix-clone-pujovic[.]vercel[.]app
“Netflix Clone - Login/Register”
netflix-clone-pujovic.vercel.app — 内容不可用. 品牌冒充:Netflix; 诈骗类型:Generic Phishing. 证据摘要: VirusTotal 19/95 (ADMINUSLabs, alphaMountain.ai, BitDefender, CyRadar, DNS8); URLScan malicious verdict; CF Radar malicious; PhishDestroy score 100/100. 注册商: Tucows.
为保留原始取证记录,下方的 PhishDestroy AI 详细分析仍使用英文。
The domain netflix-clone-pujovic.vercel.app was registered on February 23, 2026 through Tucows Domains Inc. and resolves to the IP address 216.198.79.67, which belongs to the Amazon.com, Inc. network (AS16509) located in the United States. The site returned HTTP status code 451, indicating that the content was unavailable for legal reasons, and the SSL certificate was issued by Google Trust Services under the WR1 label, confirming proper TLS deployment. Technical fingerprints reveal a modern web stack comprised of Node.js, React, Next.js, Vercel hosting, HSTS enforcement, and Webpack bundling, all consistent with a dynamically generated application rather than a static counterfeit page.
The page title "Netflix Clone - Login/Register" and the classification as brand impersonation align the infrastructure with a targeted effort to mimic the Netflix brand. Security telemetry shows that 19 of 95 VirusTotal scanners flagged the domain, and it is currently listed on one external blocklist, specifically PhishDestroy, which has taken the domain offline. Additionally, Gridinsoft assigned a trust score of 0 out of 100, indicating maximal suspicion.
While the domain is no longer reachable, the combination of a recent registration, Amazon-hosted IP, low trust rating, multiple vendor detections, and explicit brand impersonation suggests a high likelihood of malicious intent aimed at credential harvesting. Defenders should continue to block the domain at network perimeters, update URL filtering policies to include the host and its IP range, and monitor for any similar subdomains that reuse the same Vercel deployment pattern. Threat intelligence feeds should be refreshed to capture any re‑registration attempts, and incident response teams should advise users to report unsolicited login prompts claiming to be from Netflix, referencing the observed page title as a known indicator of compromise.
网络安全情报
威胁响应 Pipeline
公共封禁名单状态
所用技术 · 6 identified
JavaScript runtime built on Chrome V8 engine for server-side development.
JavaScript library for building user interfaces with component-based architecture.
Cloud platform for frontend deployment, optimized for Next.js.
React framework for production with hybrid static and server rendering.
HTTP Strict Transport Security — forces browsers to use HTTPS connections only.
Module bundler for modern JavaScript applications.
VirusTotal 分析
存档证据
网站性能分析
Google PageSpeed Insights — mobile performance audit of netflix-clone-pujovic.vercel.app · checked Mar 1, 2026
证据与外部报告
您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。