kavishkadileepa01[.]github[.]io
“Login - Spotify”
ملاحظة محفوظة
تباين العناوين المرصود
The domain kavishkadileepa01.github.io is currently operating as an active credential theft site specifically impersonating Spotify. Analysis indicates the page title explicitly displays "Login - Spotify," confirming its intent to harvest user credentials by mimicking the legitimate music streaming service. This infrastructure remains active as of the latest verification. Infrastructure analysis reveals the domain is hosted on GitHub Pages, resolving to the IP address 185.199.108.153, which is geolocated in the United States under AS54113 (Fastly, Inc.). The SSL certificate is issued by Let's Encrypt (R12), a common choice for both legitimate and malicious sites. Security telemetry shows the domain is flagged by 5 of 95 vendors on VirusTotal and appears on one security blocklist. The registrar is GitHub, Inc., and no historical registration data suggests prolonged abuse, though the seed identifier fc780b links it to a distinct phishing campaign. Current status confirms the domain remains active and continues to host the fraudulent Spotify login interface. Users encountering this domain are advised to avoid interaction entirely, as any entered credentials will be transmitted to threat actors. Organizations should block the domain at the DNS or proxy level and monitor for related indicators, including the IP 185.199.108.153 and SSL certificate thumbprint. Endpoint protection systems should be updated to recognize this infrastructure, and users should be educated to verify domain authenticity before entering credentials, particularly when redirected from unsolicited communications.
مسار الاستجابة للتهديدات Pipeline
تغطية قوائم الحظر
١٠ مصادر · تمت المزامنة 10/08/2026
التقنيات
حُدّدت ٣ تقنيات عالية الثقة
تحليل VirusTotal
تحليل أداء الموقع
Google PageSpeed Insights — mobile performance audit of kavishkadileepa01.github.io · checked Jun 1, 2026
هل تأثرت بهذا الموقع؟
إذا أدخلت بيانات اعتماد الحساب أو المعلومات الشخصية أو معلومات الدفع أو قمت بتنزيل ملف من هذا النطاق، فاتخذ إجراءً فوريًا. فيما يلي موارد لمساعدتك في الإبلاغ عن الحادث وحماية نفسك.
أبلغ السلطات المحلية
حدد بلدك للحصول على الاتصالات الرسمية المتعلقة بالجرائم الإلكترونية أو إنشاء مسودة شكوى →.
تحقق من أي نطاق
تحليل التهديدات باستخدام قائمة الحظر المخزنة، وWHOIS، وDNS، وأدلة الفحص العامة
امسح الآنالإبلاغ عن محاولة تصيد احتيالي
أرسل النطاقات المشبوهة إلى قاعدة بيانات التهديدات الخاصة بنا — ساهم في حماية المجتمع
إبلاغتحديثات فورية حول التهديدات
تقارير التصيد الاحتيالي الأخيرة وتغييرات التوفر الملحوظة
مراقبةابقَ على اطلاع، وابقَ آمنًا
راقب التهديدات في الوقت الفعلي أو اعترض على هذا الإدراج إذا كنت تعتقد أنه إنذار كاذب