MALICIOUS — CRITICAL
cse23r01a05cq[.]github[.]io
7 of 91 security engines flagged the domain; the latest stored check returned HTTP 404.
- VirusTotal
- 7/91
- Blocklists
- No stored match
- 可用性
- コンテンツが利用できません · HTTP 404
Do not enter credentials, seed phrases, payment details, or personal information on this domain.
Jump to section
cse23r01a05cq.github.io — コンテンツが利用できません (HTTP 404). ブランドの偽装: Amazon; 詐欺タイプ: Credential Phishing. 証拠の概要: VirusTotal 7/91 (alphaMountain.ai, Emsisoft, G-Data, Gridinsoft, Netcraft); URLQuery 1 alert; URLScan malicious verdict; PhishDestroy score 71/100. レジストラ: GitHub.
元のフォレンジック記録を保持するため、下の PhishDestroy AI 詳細分析は英語のままです。
Evidence Digest
cse23r01a05cq.github.io is classified critical with an evidence score of 71/100. 7 of 91 security engines flagged the domain. Registered 16 Jun 2026 via GitHub, Inc., hosted on 185.199.108.153 (Fastly, Inc., US). The latest stored check on 9 Aug 2026 returned HTTP 404 and includes a capture.
Stored generated summary (templated)mistral · 2026年6月25日
Retained for the record. This text repeats stored detection facts and is not presented as authored analysis.
This domain, cse23r01a05cq.github.io, is actively hosting a credential harvesting phishing page designed to mimic legitimate login portals. Analysis indicates the site targets users by presenting fraudulent authentication forms, likely impersonating corporate or cloud service providers to capture usernames, passwords, and potentially multi-factor authentication tokens. The infrastructure leverages GitHub Pages, a legitimate hosting service, to evade initial suspicion and blend in with benign traffic patterns. Evidence confirms the domain is flagged by 15 out of 95 security vendors on VirusTotal, with one additional entry on a security blocklist. The domain is registered through GitHub, Inc., and resolves to the IP address 185.199.108.153, a known GitHub Pages endpoint. The SSL certificate is issued by Let's Encrypt (R12), providing a false sense of security to unsuspecting visitors. Despite its benign hosting origin, the domain exhibits high-risk indicators consistent with credential theft campaigns. Users who have visited cse23r01a05cq.github.io or entered credentials on the site should immediately revoke any submitted passwords and enable multi-factor authentication on all associated accounts. Monitor financial and identity-related services for unauthorized activity, as stolen credentials may be exploited for further compromise. Network administrators should block the domain and its resolving IP at the perimeter, and review logs for connections to 185.199.108.153. If browser sessions were active during the visit, clear cached data and run a full antivirus scan to detect potential malware or session hijacking artifacts.
データの網羅性12 recorded checks
ネットワークセキュリティインテリジェンス
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| DNS4EU | cse23r01a05cq.github.io |
malicious | Sinkholed |
脅威対応 Pipeline
公開ブロックリスト登録状況
使用技術 · 3 identified
Fastly is a cloud computing services provider. Fastly's cloud platform provides a content delivery network, Internet security services, load balancing, and video & streaming services.
www.fastly.com 信頼度 100%VirusTotalによる分析
証拠および外部報告書Independent lookups and source reports
Victim safety and official reportingImmediate actions and verified reporting channels
アカウント資格情報、個人情報、支払い情報を入力した場合、またはこのドメインからファイルをダウンロードした場合は、すぐに対処してください。インシデントを報告し、自分自身を守るのに役立つリソースを以下に示します。
お住まいの地域の当局へ報告してください
サイバー犯罪の公式連絡先 または 苦情草稿を作成する → を取得するには、国を選択してください。