davidblasco1992-spec[.]github[.]io
“Site not found · GitHub Pages”
PhishDestroy identifies davidblasco1992-spec.github.io as an active phishing site designed to harvest user credentials through a fraudulent login interface. This domain masquerades as a legitimate service, specifically targeting individuals who may mistake it for an authentic profile or resource hosted on GitHub Pages. The threat actor leverages the trusted .github.io subdomain to bypass initial scrutiny, deploying a convincing replica of a login or authentication page to trick victims into submitting sensitive information such as usernames, passwords, or financial details. Once harvested, the credentials are likely used for account takeover, financial fraud, or further social engineering attacks.
This domain was flagged by 6 out of 95 security vendors on VirusTotal, indicating a high level of evasion from detection systems. It resolves to IP address 185.199.108.153, which is part of GitHub’s infrastructure but is being abused for malicious hosting. The domain was registered through GitHub, Inc., which provides no indication of the threat actor’s identity due to GitHub’s privacy protections for Pages users. Despite the legitimate registration path, the domain exhibits clear malicious intent through its impersonation of a login interface and the presence of multiple security vendor detections. The combination of a trusted hosting provider, low detection rate, and active phishing content elevates the risk to users who interact with it.
Users who have visited this domain should immediately assess whether they entered any credentials or personal information. If credentials were submitted, change passwords on all related accounts immediately and enable multi-factor authentication where possible. Avoid using saved passwords or autofill features on this site. Report the domain to your IT department or security team, and consider running a malware scan to detect any potential follow-on infections. Do not interact further with this domain or any linked content. To stay protected, always verify URLs before entering sensitive data and use browser extensions or security tools that flag known phishing sites. For a detailed investigation and indicators of compromise, refer to the full threat report associated with seed 331dd8.
네트워크 보안 인텔리전스
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| YARAhub by abuse.ch | davidblasco1992-spec.github.io/autenticacion-meta/ |
malware | Detects file containing Telegram Bot API |
| DNS4EU | davidblasco1992-spec.github.io |
malicious | Sinkholed |
위협 대응 Pipeline
차단 목록 범위
출처 10개 · 2026년 8월 10일 동기화
기술
신뢰도가 높은 기술 3개 식별
VirusTotal 분석
사이트 성능 분석
Google PageSpeed Insights — mobile performance audit of davidblasco1992-spec.github.io · checked May 9, 2026
이 사이트로 인해 영향을 받으셨나요?
계정 자격 증명, 개인 정보 또는 결제 정보를 입력했거나 이 도메인에서 파일을 다운로드한 경우 즉시 조치를 취하세요. 다음은 사건을 신고하고 자신을 보호하는 데 도움이 되는 리소스입니다.
지역 당국에 신고하십시오
공식 사이버 범죄 연락처 또는 불만사항 초안 작성 →를 받으려면 국가를 선택하세요.
모든 도메인 확인
저장된 차단 목록, WHOIS, DNS 및 공개 스캔 증거를 사용한 위협 분석
지금 스캔하기피싱 신고
의심스러운 도메인을 당사의 위협 데이터베이스에 신고해 주세요 — 커뮤니티를 보호해 주세요
보고서실시간 위협 정보
최근 피싱 보고서 및 관찰된 가용성 변경 사항
모니터링