spotify15[.]netlify[.]app
“Spotify - Web Player: Music for everyone”
证据摘要
On July 24, 2026 the domain spotify15.netlify.app was observed to be actively serving malicious content. The domain appears on two public phishing blocklists, specifically PhishDestroy and OpenPhish, indicating that it has been identified by independent threat‑intelligence feeds. Registration information shows the site was created through Netlify, a popular static‑site hosting service, and the domain resolves to the IP address 35.157.26.135, which belongs to Netlify’s shared infrastructure. DNS queries for authoritative name servers returned no results (NS_NOT_FOUND), suggesting that the domain relies on Netlify’s default DNS handling rather than custom name‑server configuration.
VirusTotal analysis reports that 15 of 91 scanning engines flagged the domain as malicious, providing additional corroboration of its hostile nature. The current status is listed as active, meaning the site continues to resolve and respond to client requests. No public page title, SSL/TLS certificate details, HTTP response codes, or Safe Browsing/OTX entries are available in the supplied intelligence, leaving those aspects of the payload unverified.
Given the confirmed blocklist listings, the Netlify hosting association, and the multi‑engine detection on VirusTotal, defenders should treat the domain as high‑risk. Recommended mitigation steps include adding spotify15.netlify.app to DNS‑based deny lists, configuring web‑proxy filters to block HTTP requests to the resolved IP 35.157.26.135, and monitoring Netlify‑associated traffic for similar patterns. Continuous re‑evaluation is advised, as changes to the site’s content, SSL configuration, or hosting could alter its threat profile.
Data Coverage
网络安全情报
威胁响应 Pipeline
阻止列表覆盖
监控中的外部数据源 10 个 · 已存快照 2026年8月12日
技术
识别出 2 项高置信度技术
VirusTotal 分析
存档证据
网站性能分析
Google PageSpeed Insights — mobile performance audit of spotify15.netlify.app · checked Jul 24, 2026
您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。
检查任意域名
使用存储的阻止列表、WHOIS、DNS 和公共扫描证据进行威胁分析
立即扫描举报网络钓鱼
将可疑域名提交至我们的威胁数据库——保护社区
报告实时威胁动态
最近的网络钓鱼报告和观察到的可用性变化
监控