# itqaakhlaq.github.io — MALICIOUS > itqaakhlaq.github.io hosts a fake Quran Academy phishing page. 17/95 scanners flag it. Check the full report for safety steps. ## Summary PhishDestroy identifies itqaakhlaq.github.io as a live phishing domain impersonating a Quran Academy to harvest user credentials and payment data. This site is part of a generic drainer kit deployed on GitHub Pages, leveraging religious themes to bypass email filters and social-engineering defenses. The kit’s landing page mirrors a legitimate Islamic education portal, presenting fake course enrollment forms that exfiltrate entered credentials and cryptocurrency wallet details directly to attacker-controlled endpoints. Security telemetry confirms the domain is weaponized for immediate financial and identity theft against Arabic-speaking users interested in online Quranic studies. Technical indicators corroborate the hostile nature of itqaakhlaq.github.io. VirusTotal reports detection by 17 of 95 participating security vendors. The domain was registered through GitHub, Inc. and resolves to IP address 185.199.108.153. Google Safe Browsing lists the domain under SOCIAL_ENGINEERING with an active malicious classification. The Let’s Encrypt SSL certificate provides a false veneer of legitimacy, while historical telemetry indicates creation within the past 90 days. The domain remains active and poses a high risk to unwary visitors. GitHub has not yet suspended the repository hosting the phishing content, leaving the page accessible to potential victims. Users should avoid interacting with any links from unsolicited emails or social media posts referencing Quran Academy courses or similar religious education offers. Immediate mitigation includes blocking the domain at DNS and network levels, clearing cached credentials, and reporting the page to Google Safe Browsing and local CERT teams. Despite these measures, residual risk persists while the page remains accessible on GitHub Pages infrastructure. ## Threat Details - Verdict: MALICIOUS - Site status: unknown (HTTP ?) ## Domain Intelligence - Registrar: GitHub, Inc. - IP: 185.199.108.153 ## Detection Status - VirusTotal: 17 vendors flagged - Google Safe Browsing: FLAGGED - Blocklists: 0 hits ## Evidence - Cloudflare Radar: https://radar.cloudflare.com/scan/8b550d2a-126b-4b83-830e-6c2809d25014 - PhishDestroy: https://phishdestroy.io/domain/itqaakhlaq.github.io/ - LLM endpoint: https://phishdestroy.io/domain/itqaakhlaq.github.io/llm.txt ## If You Visited This Site 1. Change any passwords you may have entered 2. Enable 2FA on all related accounts 3. Monitor your accounts for unauthorized activity 4. Report to: FBI IC3, Europol, local authorities --- Report by PhishDestroy | https://phishdestroy.io/domain/itqaakhlaq.github.io/ Last updated: 2026-04-12