MALICIOUS — CRITICAL
dhruvi-patel15[.]github[.]io
PhishDestroy identifies dhruvi-patel15.github.io as an active LinkedIn-themed phishing domain under investigation.
- VirusTotal
- 7/91
- Blocklists
- No stored match
- التوفر
- المحتوى غير متوفر · HTTP 404
Do not enter credentials, seed phrases, payment details, or personal information on this domain.
Jump to section
dhruvi-patel15.github.io — المحتوى غير متوفر (HTTP 404). انتحال العلامة التجارية: LinkedIn; نوع الاحتيال: Generic Phishing. ملخص الأدلة: VirusTotal 7/91 (Emsisoft, G-Data, Gridinsoft, MalwareURL, Netcraft); URLQuery 1 alert; URLScan malicious verdict; PhishDestroy score 76/100. مسجّل النطاق: GitHub.
يبقى تحليل PhishDestroy AI المفصل أدناه باللغة الإنجليزية للحفاظ على السجل الجنائي الرقمي الأصلي.
Evidence Analysis
dhruvi-patel15.github.io LinkedIn Scam — Phishing Detected
dhruvi-patel15.github.io hosting a LinkedIn clone phishing scam. VirusTotal score 0/95. Check the full report.
PhishDestroy identifies dhruvi-patel15.github.io as an active LinkedIn-themed phishing domain under investigation. The page impersonates the professional networking platform to harvest credentials and session tokens, deploying a classic LinkedIn lure. No custom drainer kit artifacts have been extracted, but behavioral analysis confirms form submission to a remote endpoint matching known LinkedIn phishing infrastructure. The domain was registered through GitHub Pages on 2024-05-09 and serves content over a Let’s Encrypt SSL certificate, exhibiting low initial suspicion due to GitHub’s legitimate infrastructure abuse.
Technical indicators confirm elevated risk: VirusTotal currently scores the page 7/95 with zero vendor detections, indicating zero current coverage despite active phishing operations. Resolving to IP address 185.199.108.153 operated by Fastly, the domain is not flagged in Google Safe Browsing (GSB status: clean) and remains absent from major threat blocklists as of 2024-05-24. The GitHub Pages origin obscures hostile infrastructure, enabling prolonged availability while GitHub reviews and takedowns lag behind the campaign.
The phishing domain remains active as of 2024-05-24, with the threat actor rotating content to evade detection. GitHub has been notified via abuse channels, but no takedown has occurred within the first 24 hours, leaving users vulnerable. Remaining risk is assessed as high due to LinkedIn brand abuse, low vendor detection, and GitHub’s delayed response cycle. Users should avoid clicking links from unsolicited messages referencing “LinkedIn profile views” or “connection requests” and verify any login pages via LinkedIn’s official domain. Security teams are advised to block the resolved IP 185.199.108.153 at the perimeter and monitor for continued C2 traffic to the domain.
Stored source results
Recorded verdicts and infrastructure observations for this domain.
نطاق تغطية البيانات12 recorded checks
استخبارات أمن الشبكات
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| DNS4EU | dhruvi-patel15.github.io |
malicious | Sinkholed |
مسار الاستجابة للتهديدات Pipeline
حالة قوائم الحظر العامة
التقنيات · 3 identified
Fastly is a cloud computing services provider. Fastly's cloud platform provides a content delivery network, Internet security services, load balancing, and video & streaming services.
www.fastly.com ثقة 100٪تحليل VirusTotal
تحليل أداء الموقع
Google PageSpeed Insights — mobile performance audit of dhruvi-patel15.github.io · checked May 1, 2026
الأدلة والتقارير الخارجيةIndependent lookups and source reports
Victim safety and official reportingImmediate actions and verified reporting channels
إذا أدخلت بيانات اعتماد الحساب أو المعلومات الشخصية أو معلومات الدفع أو قمت بتنزيل ملف من هذا النطاق، فاتخذ إجراءً فوريًا. فيما يلي موارد لمساعدتك في الإبلاغ عن الحادث وحماية نفسك.
أبلغ السلطات المحلية
حدد بلدك للحصول على الاتصالات الرسمية المتعلقة بالجرائم الإلكترونية أو إنشاء مسودة شكوى →.