kriisshhnnaa[.]github[.]io
Verifica phishing e sicurezza per kriisshhnnaa.github.io
“Site not found · GitHub Pages”
kriisshhnnaa.github.io — Contenuto non disponibile (HTTP 404). Simulazione del marchio: Netflix; Tipo di truffa: Credential Phishing. Riepilogo delle prove: VirusTotal 14/91 (alphaMountain.ai, BitDefender, Certego, CyRadar, ESET); URLScan malicious verdict; Google Safe Browsing flagged; PhishDestroy score 92/100. Registrar: GitHub Pages.
L’analisi dettagliata di PhishDestroy AI resta in inglese per preservare il rapporto forense originale.
Evidence Analysis
The domain kriisshhnnaa.github.io is currently flagged as an active credential theft phishing site. Analysis indicates the infrastructure is designed to harvest user login credentials, likely through fake authentication portals or cloned login pages. The domain remains operational and has not been taken down despite detection by multiple security mechanisms. Infrastructure analysis reveals the domain is hosted on GitHub Pages and resolves to the IP address 185.199.111.153, registered under AS54113 (Fastly, Inc.) in the United States. The SSL certificate is issued by Let's Encrypt (R12), a common choice for both legitimate and malicious sites. Security vendors have flagged this domain in 14 of 95 VirusTotal scans, with one additional entry on a security blocklist. Google Safe Browsing explicitly designates the domain as phishing, and it is blocked by at least one threat intelligence feed. The page title, 'Site not found · GitHub Pages,' suggests an attempt to mimic legitimate GitHub Pages errors while potentially serving malicious content through obfuscated redirects or hidden scripts. Current status confirms the domain remains active and unresolved. Organizations and individuals are advised to block the domain at the DNS or network level to prevent credential exposure. Endpoint protection systems should be updated to include this indicator of compromise (IOC) in their threat intelligence feeds. Users who may have interacted with the domain should immediately reset credentials for any accounts accessed during the exposure window. Monitoring for unusual authentication attempts or unauthorized access is recommended, particularly for accounts linked to GitHub or other development platforms.
Copertura dei dati12 recorded checks
Pipeline di risposta alle minacce
Stato della lista di blocco pubblica
Tecnologie · 3 identified
Fastly is a cloud computing services provider. Fastly's cloud platform provides a content delivery network, Internet security services, load balancing, and video & streaming services.
www.fastly.com Confidenza al 100%Analisi di VirusTotal
Dati e relazioni esterneIndependent lookups and source reports
Victim safety and official reportingImmediate actions and verified reporting channels
Se hai inserito credenziali dell'account, informazioni personali o di pagamento oppure hai scaricato un file da questo dominio, agisci immediatamente. Di seguito sono riportate le risorse per aiutarti a segnalare l'incidente e proteggerti.
Segnalalo alle autorità locali
Seleziona il tuo Paese per ottenere contatti ufficiali del crimine informatico o creare una bozza di reclamo →.