sakshiphulwale[.]github[.]io
Verifica phishing e sicurezza per sakshiphulwale.github.io
“Amazon”
sakshiphulwale.github.io — Contenuto non disponibile (HTTP 404). Simulazione del marchio: Google; Tipo di truffa: Brand Impersonation. Riepilogo delle prove: VirusTotal 9/91 (CyRadar, Emsisoft, Forcepoint ThreatSeeker, G-Data, Google Safebrowsing); Google Safe Browsing flagged; PhishDestroy score 80/100. Registrar: GitHub.
L’analisi dettagliata di PhishDestroy AI resta in inglese per preservare il rapporto forense originale.
This domain, sakshiphulwale.github.io, poses a high-risk threat through targeted brand impersonation of Google, a tactic commonly employed to harvest user credentials or distribute malicious payloads. The page title, 'Amazon,' further indicates an attempt to mislead users by presenting content inconsistent with the impersonated brand, increasing the likelihood of successful deception. Analysis of the domain's infrastructure reveals it is designed to exploit trust in legitimate services, potentially leading to account compromise, unauthorized data access, or secondary malware infections. Evidence supporting the malicious nature of this domain includes detection by 9 out of 95 security vendors on VirusTotal, with Google Safe Browsing explicitly flagging it as phishing. The domain is hosted on GitHub's infrastructure, resolving to the IPv6 address 2606:50c0:8001::153, which is geolocated in the United States under AS54113 (Fastly, Inc.). The SSL certificate is issued by Let's Encrypt (R12), a common choice for both legitimate and malicious sites due to its accessibility. The domain appears on one security blocklist and is actively blocked by at least one threat intelligence feed, reinforcing its classification as a confirmed threat. Users who have visited sakshiphulwale.github.io should immediately cease all interaction with the domain and perform a security audit of their systems. If credentials were entered, they must be changed from a secure device, and multi-factor authentication should be enabled where available. Network-level blocking of the domain and its associated IP (2606:50c0:80c0::153) is recommended for organizations to prevent further exposure. Monitoring for unusual account activity or unauthorized access attempts is critical, as this domain's primary objective is credential theft or follow-on exploitation.
Pipeline di risposta alle minacce
Stato della lista di blocco pubblica
Tecnologie · 3 identified
Fastly is a cloud computing services provider. Fastly's cloud platform provides a content delivery network, Internet security services, load balancing, and video & streaming services.
www.fastly.com Confidenza al 100%Analisi di VirusTotal
Dati e relazioni esterne
Questo sito ti ha influenzato in qualche modo?
Se hai inserito credenziali dell'account, informazioni personali o di pagamento oppure hai scaricato un file da questo dominio, agisci immediatamente. Di seguito sono riportate le risorse per aiutarti a segnalare l'incidente e proteggerti.
Segnalalo alle autorità locali
Seleziona il tuo Paese per ottenere contatti ufficiali del crimine informatico o creare una bozza di reclamo →.
Verifica qualsiasi dominio
Analisi delle minacce utilizzando blocklist archiviate, WHOIS, DNS e prove di scansione pubblica
Scansiona oraSegnala un tentativo di phishing
Segnala i domini sospetti al nostro database delle minacce — proteggi la comunità
SegnalaFeed in tempo reale sulle minacce
Segnalazioni recenti di phishing e modifiche osservate della disponibilità
MonitoraRimani informato, rimani al sicuro
Controlla le minacce in tempo reale oppure contesta questa segnalazione se ritieni che si tratti di un falso positivo