instgram-pist-muscle-ginxl9n.netlify.app
Category: Phishing
To use full-featured product, you have to purchase a license for Combo Cleaner. Limited seven days free trial available. Combo Cleaner is owned and operated by RCS LT, the parent company of PCRisk.com.
Description of instgram-pist-muscle-ginxl9n.netlify.app
This domain appears to host a page designed to resemble Instagram's login interface. The page title is "Instagram," and the screenshot shows a sign-in form in French with Instagram-style branding, a password-reset prompt, and a Meta label at the bottom. The domain itself is a Netlify subdomain rather than an official Instagram-owned web address, which suggests it may be a third-party hosted imitation rather than a legitimate social media login portal.
Based on the visible content and linked resources, the page seems intended to collect account credentials or redirect users within an Instagram-themed workflow. It references official Instagram account signup and password reset pages, which may be used to make the page appear more convincing. The site does not appear to represent an independent social platform or business with its own branding, and no clear operator identity is disclosed on the page.
Safety Assessment for instgram-pist-muscle-ginxl9n.netlify.app
This website shows multiple indicators commonly associated with credential-harvesting pages. At the time of this scan, it was flagged by 14 out of 91 security engines, and a major threat database listed it for social-engineering activity. The domain also closely imitates the Instagram name while using a third-party hosting subdomain, and the screenshot shows a login form styled to look like Instagram rather than a clearly separate service. These are strong signs that the page may be attempting to impersonate a well-known platform.
The malware file scan did not detect malicious files at the time of analysis, but that does not offset the phishing-related signals. Phishing pages often contain little or no malware and instead rely on deceptive branding and fake login forms to capture usernames and passwords. In addition, the domain's IP address appears on one mail-reputation blocklist, which is a weaker signal on its own but still adds a small amount of caution.
Based on these findings, this website may pose potential risks to visitors.
Technical Description
The site uses a valid SSL certificate issued by a mainstream certificate authority, with expiry extending to 2027-03-19. It is hosted on Netlify infrastructure backed by AWS EC2 in Frankfurt, Germany, and resolves to IP address 63.176.8.218. A valid certificate only confirms encrypted transport to the host being visited; it does not verify that the page is an official Instagram property.
DNSSEC appears to be unsigned, and the domain uses Netlify-related hosting and external assets including a JavaScript file from a GitHub Pages domain. The combination of third-party static hosting, brand-like naming, and a login page imitating a major platform may be a security concern at the time of this scan.
Share your experience with this website. Was it safe? Did you encounter any issues?