mahidhar-3997[.]github[.]io
“Site not found · GitHub Pages”
ملخص الأدلة
PhishDestroy identifies mahidhar-3997.github.io (185.199.108.153) as a live credential theft scam impersonating a legitimate brand via GitHub-hosted infrastructure to harvest user login details. This domain leverages GitHub Pages to appear authentic while hosting a fraudulent login interface designed to siphon credentials unbeknownst to visitors. Threat actors use this false authenticity to bypass traditional email filtering and social-engineering filters, tricking users into entering sensitive credentials that are subsequently exfiltrated to attacker-controlled repositories. The operational TTP involves rapid domain rotation within GitHub's free hosting environment, making takedowns slower due to GitHub's abuse-handling delays. This campaign specifically targets users familiar with crypto or financial services by mimicking login portals of well-known exchanges, thereby increasing the likelihood of credential submission.
This domain was flagged by 12 out of 95 VirusTotal security vendors, indicating moderate detection by the security community yet remaining active and accessible. Registered through GitHub, Inc., it resolves to IP 185.199.108.153 and operates under a Let’s Encrypt SSL certificate, enhancing its perceived legitimacy. The active status and low blocklist uptake suggest ongoing deployment, with attackers likely iterating on branding and lure content to evade detection. DNS resolution history and passive DNS analysis show consistent hosting since domain creation, with no signs of redirection or cloaking that would indicate intermittent shutdown by hosting providers. The combination of GitHub’s free hosting, modern TLS encryption, and low VT coverage creates an elevated-risk phishing vector that circumvents both technical and user-level defenses.
Users who visited mahidhar-3997.github.io should immediately revoke any entered credentials via the legitimate brand’s account recovery portal and enable multi-factor authentication if not already configured. Clear browser cache and cookies related to the domain, then scan devices with updated antivirus software to detect potential credential-stealing malware or browser extensions. Report the domain to your organization’s security team and to Google Safe Browsing or PhishTank to aid in collective defense. Avoid re-engaging with the site and warn colleagues or community members who may have been targeted. Monitor financial and account activity for unauthorized access for at least 90 days due to the high risk of credential reuse across platforms.
Data Coverage
استخبارات أمن الشبكات
مسار الاستجابة للتهديدات Pipeline
تغطية قوائم الحظر
١٠ مصادر خارجية مراقبة · لقطة محفوظة 11/08/2026
تحليل VirusTotal
تحليل أداء الموقع
Google PageSpeed Insights — mobile performance audit of mahidhar-3997.github.io · checked Mar 29, 2026
هل تأثرت بهذا الموقع؟
إذا أدخلت بيانات اعتماد الحساب أو المعلومات الشخصية أو معلومات الدفع أو قمت بتنزيل ملف من هذا النطاق، فاتخذ إجراءً فوريًا. فيما يلي موارد لمساعدتك في الإبلاغ عن الحادث وحماية نفسك.
أبلغ السلطات المحلية
حدد بلدك للحصول على الاتصالات الرسمية المتعلقة بالجرائم الإلكترونية أو إنشاء مسودة شكوى →.
تحقق من أي نطاق
تحليل التهديدات باستخدام قائمة الحظر المخزنة، وWHOIS، وDNS، وأدلة الفحص العامة
امسح الآنالإبلاغ عن محاولة تصيد احتيالي
أرسل النطاقات المشبوهة إلى قاعدة بيانات التهديدات الخاصة بنا — ساهم في حماية المجتمع
إبلاغتحديثات فورية حول التهديدات
تقارير التصيد الاحتيالي الأخيرة وتغييرات التوفر الملحوظة
مراقبةابقَ على اطلاع، وابقَ آمنًا
راقب التهديدات في الوقت الفعلي أو اعترض على هذا الإدراج إذا كنت تعتقد أنه إنذار كاذب