aminealmadini[.]github[.]io
“Instagram Clone”
Analysis of the domain aminealmadini.github.io indicates a confirmed brand impersonation campaign targeting Instagram, with elevated risk due to its hosting infrastructure and detection by security vendors. The domain, registered on March 29, 2026, through GitHub, Inc., resolves to the IP address 185.199.109.153, associated with Fastly, Inc. (AS54113) in the United States. Despite its current offline status (HTTP 404), the domain was flagged by 8 of 91 security vendors on VirusTotal, including PhishDestroy, which has blocked it. It also appears on at least one security blocklist, reinforcing its classification as malicious.
Infrastructure analysis reveals the use of GitHub Pages and Fastly’s content delivery network, alongside Varnish caching technology. The SSL certificate, issued by Let’s Encrypt (YR2), does not mitigate the domain’s risk, as impersonation sites frequently leverage legitimate certificates to appear credible. The page title, 'Instagram Clone,' directly corroborates the brand impersonation intent, aligning with the reported threat type. While the domain is no longer accessible, its prior detection and hosting on a widely abused platform (GitHub Pages) suggest it may have been part of a larger phishing operation.
Defenders should treat this domain as compromised and monitor for related infrastructure, such as reused IP addresses or SSL certificates. Given the absence of nameservers and the domain’s offline status, further forensic analysis may be limited, but historical DNS records or passive DNS data could provide additional context. Organizations are advised to block the domain at the network level and review logs for prior connections from internal systems.
Threat Response Pipeline
Public Blocklist Status
Technologies · 3 identified
Fastly is a cloud computing services provider. Fastly's cloud platform provides a content delivery network, Internet security services, load balancing, and video & streaming services.
www.fastly.com 100% confidenceVirusTotal Analysis
Evidence & External Reports
Were You Affected by This Site?
If credentials, payment data, or files were exposed, report the incident immediately. Change affected passwords, revoke active sessions, and scan the device.
Report to Your Local Authorities
Select your country to get official cybercrime contacts, or create a complaint draft →.
Check Any Domain
Threat analysis using stored blocklist, WHOIS, DNS, and public scan evidence
Scan NowReport Phishing
Submit suspicious domains to our threat database — protect the community
ReportLive Threat Feed
Recent phishing reports and observed availability changes
MonitorStay Informed, Stay Safe
Monitor live threats or contest this listing if you believe it's a false positive