azambeigh[.]github[.]io
“Site not found · GitHub Pages”
Zusammenfassung der Beweislage
This domain, azambeigh.github.io, is identified as an active credential theft operation leveraging GitHub Pages infrastructure to deceive users. Analysis indicates the site mimics legitimate GitHub Pages content, presenting a 'Site not found' error to mask its true intent. The threat actor likely exploits the trust associated with GitHub’s hosting service to harvest login credentials, API keys, or other sensitive data from unsuspecting developers or repository maintainers. No direct evidence of a crypto drainer kit or brand impersonation (e.g., Microsoft, Google) was observed, but the use of a benign-appearing error page suggests a low-interaction phishing tactic designed to evade initial scrutiny. Infrastructure analysis reveals the following technical indicators: the domain resolves to IP address 185.199.108.153, hosted by GitHub, Inc. in the United States. The domain was created on May 02, 2026, and is registered through GitHub, Inc., which aligns with the GitHub Pages service. The SSL certificate is issued by Let’s Encrypt (R12), a common but not inherently suspicious provider. VirusTotal detection shows 13 out of 95 security vendors flagging the domain as malicious, while it appears on one security blocklist. Notably, the domain is not currently listed in Google Safe Browsing (GSB) databases, which may contribute to its persistence. The page title, 'Site not found · GitHub Pages,' further reinforces the deception by mimicking a legitimate GitHub Pages error message. As of the latest assessment, the domain remains active and continues to resolve, posing an ongoing risk to users. The 'Site not found' page may serve as a placeholder or a preliminary phase in a multi-stage attack, where the threat actor could later deploy a more sophisticated credential harvesting interface. Users are advised to avoid interacting with this domain, particularly if redirected from unexpected sources. Organizations should consider blocking the domain at the network level and monitoring for any connections to the IP address 185.199.108.153. Given the domain’s association with GitHub Pages, administrators should also review repository access logs for unauthorized activity or anomalous credential usage. The risk level remains high due to the domain’s active status, lack of GSB listing, and potential for credential theft targeting technical audiences.
Data Coverage
Erkenntnisse zur Netzwerksicherheit
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| DNS4EU | azambeigh.github.io |
malicious | Sinkholed |
Pipeline zur Reaktion auf Sicherheitsbedrohungen
Blocklistenabdeckung
10 überwachte externe Feeds · gespeicherter Stand 11.08.2026
Technologien
3 Technologien mit hoher Konfidenz erkannt
VirusTotal-Analyse
Website-Performanceanalyse
Google PageSpeed Insights — mobile performance audit of azambeigh.github.io · checked May 2, 2026
Wurden Sie von dieser Website betroffen?
Wenn Sie Kontoanmeldeinformationen, persönliche oder Zahlungsinformationen eingegeben oder eine Datei von dieser Domain heruntergeladen haben, ergreifen Sie sofort Maßnahmen. Nachfolgend finden Sie Ressourcen, die Ihnen helfen, den Vorfall zu melden und sich zu schützen.
Melden Sie sich bei Ihren örtlichen Behörden
Wählen Sie Ihr Land aus, um Offizielle Kontakte im Bereich Cyberkriminalität oder einen Beschwerdeentwurf erstellen → zu erhalten.
Jede beliebige Domain prüfen
Bedrohungsanalyse anhand gespeicherter Blocklisten, WHOIS, DNS und öffentlicher Scan-Beweise
Jetzt scannenPhishing melden
Melden Sie verdächtige Domains an unsere Bedrohungsdatenbank – schützen Sie die Community
MeldenEchtzeit-Bedrohungsfeed
Aktuelle Phishing-Meldungen und beobachtete Verfügbarkeitsänderungen
ÜberwachenBleiben Sie auf dem Laufenden, bleiben Sie sicher
Beobachten Sie aktuelle Bedrohungen oder legen Sie Widerspruch gegen diesen Eintrag ein, wenn Sie der Meinung sind, dass es sich um einen Fehlalarm handelt