MALICIOUS — CRITICAL
Is jeona36.github.io a Credential Theft Scam?
jeona36[.]
The domain jeona36.github.io is currently active and identified as a credential theft phishing operation.
- VirusTotal
- 12/92
- Blocklists
- No stored match
- Disponibilità
- Contenuto non disponibile · HTTP 404
Do not enter credentials, seed phrases, payment details, or personal information on this domain.
Jump to section
jeona36.github.io — Contenuto non disponibile (HTTP 404). Simulazione del marchio: Amazon; Tipo di truffa: Credential Phishing. Riepilogo delle prove: VirusTotal 12/92 (ADMINUSLabs, Criminal IP, alphaMountain.ai, Certego, Emsisoft); URLQuery 1 alert; URLScan malicious verdict; PhishDestroy score 86/100. Registrar: GitHub.
L’analisi dettagliata di PhishDestroy AI resta in inglese per preservare il rapporto forense originale.
Evidence Analysis
The domain jeona36.github.io is currently active and identified as a credential theft phishing operation. Analysis indicates the infrastructure is designed to harvest user login credentials, likely targeting unsuspecting victims through deceptive login portals. The domain remains accessible despite its malicious intent, posing a high risk to users who may encounter it through phishing links or redirects. Infrastructure analysis reveals the domain is flagged by 12 of 95 security vendors on VirusTotal, indicating widespread detection. It resolves to the IP address 185.199.109.153, hosted by GitHub, Inc., and appears on at least one security blocklist. The SSL certificate is issued by Let’s Encrypt (R12), a common choice for both legitimate and malicious sites. The domain was registered through GitHub, Inc., with a creation date of May 16, 2026, which may suggest an attempt to appear legitimate or exploit misconfigured records. The page currently displays a 'Site not found' message, though this could be a temporary state or a cloaking technique to evade detection. As of the latest verification, jeona36.github.io remains active and should be treated as a confirmed threat. Users are advised to avoid interacting with the domain, block it at the network level, and report any phishing attempts to their security teams. Organizations should update their web filters to include this domain and monitor for related indicators of compromise, such as the associated IP address. If credentials were previously entered on this site, immediate password resets and multi-factor authentication enforcement are recommended for all affected accounts.
Stored source results
Recorded verdicts and infrastructure observations for this domain.
Copertura dei dati12 recorded checks
Informazioni sulla sicurezza di rete
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| DNS4EU | jeona36.github.io |
malicious | Sinkholed |
Pipeline di risposta alle minacce
Stato della lista di blocco pubblica
Tecnologie · 3 identified
Fastly is a cloud computing services provider. Fastly's cloud platform provides a content delivery network, Internet security services, load balancing, and video & streaming services.
www.fastly.com Confidenza al 100%Analisi di VirusTotal
Analisi delle prestazioni del sito
Google PageSpeed Insights — mobile performance audit of jeona36.github.io · checked May 16, 2026
Dati e relazioni esterneIndependent lookups and source reports
Victim safety and official reportingImmediate actions and verified reporting channels
Se hai inserito credenziali dell'account, informazioni personali o di pagamento oppure hai scaricato un file da questo dominio, agisci immediatamente. Di seguito sono riportate le risorse per aiutarti a segnalare l'incidente e proteggerti.
Segnalalo alle autorità locali
Seleziona il tuo Paese per ottenere contatti ufficiali del crimine informatico o creare una bozza di reclamo →.