mahidhar-3997[.]github[.]io
“Site not found · GitHub Pages”
Riepilogo delle prove
PhishDestroy identifies mahidhar-3997.github.io (185.199.108.153) as a live credential theft scam impersonating a legitimate brand via GitHub-hosted infrastructure to harvest user login details. This domain leverages GitHub Pages to appear authentic while hosting a fraudulent login interface designed to siphon credentials unbeknownst to visitors. Threat actors use this false authenticity to bypass traditional email filtering and social-engineering filters, tricking users into entering sensitive credentials that are subsequently exfiltrated to attacker-controlled repositories. The operational TTP involves rapid domain rotation within GitHub's free hosting environment, making takedowns slower due to GitHub's abuse-handling delays. This campaign specifically targets users familiar with crypto or financial services by mimicking login portals of well-known exchanges, thereby increasing the likelihood of credential submission.
This domain was flagged by 12 out of 95 VirusTotal security vendors, indicating moderate detection by the security community yet remaining active and accessible. Registered through GitHub, Inc., it resolves to IP 185.199.108.153 and operates under a Let’s Encrypt SSL certificate, enhancing its perceived legitimacy. The active status and low blocklist uptake suggest ongoing deployment, with attackers likely iterating on branding and lure content to evade detection. DNS resolution history and passive DNS analysis show consistent hosting since domain creation, with no signs of redirection or cloaking that would indicate intermittent shutdown by hosting providers. The combination of GitHub’s free hosting, modern TLS encryption, and low VT coverage creates an elevated-risk phishing vector that circumvents both technical and user-level defenses.
Users who visited mahidhar-3997.github.io should immediately revoke any entered credentials via the legitimate brand’s account recovery portal and enable multi-factor authentication if not already configured. Clear browser cache and cookies related to the domain, then scan devices with updated antivirus software to detect potential credential-stealing malware or browser extensions. Report the domain to your organization’s security team and to Google Safe Browsing or PhishTank to aid in collective defense. Avoid re-engaging with the site and warn colleagues or community members who may have been targeted. Monitor financial and account activity for unauthorized access for at least 90 days due to the high risk of credential reuse across platforms.
Data Coverage
Informazioni sulla sicurezza di rete
Pipeline di risposta alle minacce
Copertura delle blocklist
10 fonti esterne monitorate · snapshot del 10/08/2026
10 fonti esterne monitorate Nessuna corrispondenza
Analisi di VirusTotal
Analisi delle prestazioni del sito
Google PageSpeed Insights — mobile performance audit of mahidhar-3997.github.io · checked Mar 29, 2026
Questo sito ti ha influenzato in qualche modo?
Se hai inserito credenziali dell'account, informazioni personali o di pagamento oppure hai scaricato un file da questo dominio, agisci immediatamente. Di seguito sono riportate le risorse per aiutarti a segnalare l'incidente e proteggerti.
Segnalalo alle autorità locali
Seleziona il tuo Paese per ottenere contatti ufficiali del crimine informatico o creare una bozza di reclamo →.
Verifica qualsiasi dominio
Analisi delle minacce utilizzando blocklist archiviate, WHOIS, DNS e prove di scansione pubblica
Scansiona oraSegnala un tentativo di phishing
Segnala i domini sospetti al nostro database delle minacce — proteggi la comunità
SegnalaFeed in tempo reale sulle minacce
Segnalazioni recenti di phishing e modifiche osservate della disponibilità
MonitoraRimani informato, rimani al sicuro
Controlla le minacce in tempo reale oppure contesta questa segnalazione se ritieni che si tratti di un falso positivo