netflix-clone-sigma-hazel.vercel.app
Category: Phishing
To use full-featured product, you have to purchase a license for Combo Cleaner. Limited seven days free trial available. Combo Cleaner is owned and operated by RCS LT, the parent company of PCRisk.com.
Description of netflix-clone-sigma-hazel.vercel.app
This domain hosts a web application titled "Netflix Clone" on a Vercel subdomain. Based on the page title, screenshot, and visible interface, it appears to imitate the look and branding style of Netflix, presenting a sign-in form over a background of movie and TV artwork. The page includes email and password fields along with social-login style buttons, suggesting it is designed to collect user credentials or simulate a streaming-service login experience.
The site does not appear to represent an official Netflix-owned domain. Instead, it looks like a cloned or demo-style project deployed on shared cloud hosting under vercel.app. While some such projects are created for development or portfolio purposes, the use of a recognizable entertainment brand name together with a live login page means the site may be interpreted as an imitation of a well-known service rather than an independent media platform.
Safety Assessment for netflix-clone-sigma-hazel.vercel.app
Multiple security engines flagged this URL at the time of the scan, with 17 out of 91 detections and many of those classifying it as phishing. That level of consensus is a meaningful warning signal, especially because the page visually resembles Netflix while operating from an unrelated vercel.app subdomain. The combination of a brand-like login screen, credential fields, and third-party phishing detections increases the likelihood that the page may be intended to capture account details or otherwise mislead visitors.
At the same time, the malware scan did not identify malicious files, and the checked blacklist databases were largely clean at the time of review. That does not remove the concern, because phishing pages often rely on deceptive page design rather than downloadable malware, and blacklist coverage can lag behind newly deployed or short-lived pages.
Based on these findings, this website may pose potential risks to visitors.
Technical Description
The site is hosted on Vercel infrastructure and resolves to IP address 216.198.79.195 in the United States. It uses a valid TLS certificate issued by a mainstream certificate authority, with expiry listed as 2026-07-27. The presence of HTTPS indicates encrypted transport, but this should not be treated as proof of legitimacy because phishing pages commonly use valid certificates as well.
DNSSEC appears to be unsigned, and the domain uses Vercel nameservers. The application structure and asset paths suggest a Next.js deployment. No malicious files or flagged external links were identified in the provided malware scan, but the primary concern here appears to be deceptive content and possible credential harvesting rather than exploit delivery.
Share your experience with this website. Was it safe? Did you encounter any issues?