Phishing detection: netflixdy.pages.dev
Netflix Investigate
Domain
netflixdy.pages.dev1 CT host on apex
IP
188.114.96.3
URL
https://netflixdy.pages.dev
Cert
Google Trust Services
Phishunt analysis Beta
37
medium suspicion suspiciousheuristic risk score · not a probability
Why?
- +5.3 Keyword match
- +5.1 Site cluster
- +5.1 urlscan.io
- +4.5 Brand in title
- +4.1 Brand in screenshot
- +3.7 Brand in domain label
- +3.4 Shared IP cluster
- +1.1 ASN reputation
- +1.1 No CSP header
- +1.1 No HSTS header
- +1.0 Young domain
- +0.7 Brand in cert SAN
- +0.6 Suspicious TLD
- +0.4 Long domain
- +0.3 Free CA
- +0.1 Deep subdomain
19 signals fired · detector v3.0.0
AI analysis AIBeta
Credential harvesting
Site impersonates Netflix on a Cloudflare Pages PaaS domain with the brand name in the apex label and confirmed presence of Netflix branding in page content. Confirmed malicious by urlscan, likely targeting Netflix account credentials or payment information.
Brand in domain labelPaaS hosturlscan.io
AI-generated from stored detector signals - the AI never visited the site. · 2026-07-18 · confidence 78%
Domain & Network
Whois
Registrar
CloudFlare, Inc.
Network
IP
188.114.96.3
Country
United States
Hosting
Cloudflare, Inc.
ASN
AS13335
TLS Cert
Google Trust Services
External detection
urlscan.io
CleanGoogle Safe Browsing · OpenPhish · PhishTank · TweetFeed
Requests
Resources
Observables
Related websites
Report this phishing
Submit to blocklists
urlscan
VirusTotal
Whois
ipinfo
Greynoise