MALICIOUS — CRITICAL
Verifica phishing e sicurezza per shalini31102.github.io
shalini31102[.]
PhishDestroy identifies shalini31102.github.io as an active generic phishing domain hosting a crypto-currency drainer kit designed to harvest private keys and seed phrases.
- VirusTotal
- 13/91
- Blocklists
- No stored match
- Disponibilità
- Contenuto non disponibile · HTTP 404
Do not enter credentials, seed phrases, payment details, or personal information on this domain.
Jump to section
shalini31102.github.io — Contenuto non disponibile (HTTP 404). Simulazione del marchio: Netflix; Tipo di truffa: Crypto Drainer. Riepilogo delle prove: VirusTotal 13/91 (ADMINUSLabs, alphaMountain.ai, BitDefender, CyRadar, Emsisoft); URLQuery 1 alert; URLScan malicious verdict; Google Safe Browsing flagged; PhishDestroy score 94/100. Registrar: GitHub.
L’analisi dettagliata di PhishDestroy AI resta in inglese per preservare il rapporto forense originale.
Evidence Analysis
PhishDestroy identifies shalini31102.github.io as an active generic phishing domain hosting a crypto-currency drainer kit designed to harvest private keys and seed phrases. The domain does not impersonate a specific brand but instead presents a spoofed wallet-login interface to trick users into signing malicious transactions. The landing page leverages JavaScript-based drainer scripts embedded on the GitHub Pages site, which execute once a victim pastes credentials or connects a wallet.
Technical indicators confirm the threat: VirusTotal flags the domain at 13/95 security vendors, the IP 185.199.108.153 resolves to GitHub Pages infrastructure, and the domain is registered through GitHub, Inc. Google Safe Browsing categorizes it under SOCIAL_ENGINEERING with confirmed malicious activity. The SSL certificate issued by Let’s Encrypt provides a false sense of legitimacy, but the certificate’s short lifespan and issuance to a disposable GitHub Pages subdomain indicate opportunistic misuse.
As of the latest scan, the campaign remains active with no evidence of takedown. Users are advised to avoid clicking links to shalini31102.github.io and to verify any similar URLs using PhishDestroy’s real-time scanner. While the current risk is high due to active distribution and wallet-targeting behavior, proactive blocking and public reporting can reduce exposure. Remaining risk includes continued use in social media spam, DM campaigns on Telegram, and phishing forums. Immediate response includes domain blacklisting, browser-extension blocks, and wallet software warnings.
Stored source results
Recorded verdicts and infrastructure observations for this domain.
Copertura dei dati12 recorded checks
Informazioni sulla sicurezza di rete
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| DNS4EU | shalini31102.github.io |
malicious | Sinkholed |
Pipeline di risposta alle minacce
Stato della lista di blocco pubblica
Tecnologie · 3 identified
Fastly is a cloud computing services provider. Fastly's cloud platform provides a content delivery network, Internet security services, load balancing, and video & streaming services.
www.fastly.com Confidenza al 100%Analisi di VirusTotal
Analisi delle prestazioni del sito
Google PageSpeed Insights — mobile performance audit of shalini31102.github.io · checked May 4, 2026
Dati e relazioni esterneIndependent lookups and source reports
Victim safety and official reportingImmediate actions and verified reporting channels
Se hai inserito credenziali dell'account, informazioni personali o di pagamento oppure hai scaricato un file da questo dominio, agisci immediatamente. Di seguito sono riportate le risorse per aiutarti a segnalare l'incidente e proteggerti.
Segnalalo alle autorità locali
Seleziona il tuo Paese per ottenere contatti ufficiali del crimine informatico o creare una bozza di reclamo →.