dhruvi-patel15[.]github[.]io
dhruvi-patel15.github.io 피싱 및 보안 점검
“Site not found · GitHub Pages”
dhruvi-patel15.github.io — 콘텐츠를 사용할 수 없음 (HTTP 404). 브랜드 사칭: LinkedIn; 사기 유형: Generic Phishing. 증거 요약: VirusTotal 7/91 (Emsisoft, G-Data, Gridinsoft, MalwareURL, Netcraft); URLQuery 1 alert; URLScan malicious verdict; PhishDestroy score 76/100. 등록기관: GitHub.
원본 포렌식 기록을 보존하기 위해 아래의 상세 PhishDestroy AI 분석은 영어로 유지됩니다.
Evidence Analysis
PhishDestroy identifies dhruvi-patel15.github.io as an active LinkedIn-themed phishing domain under investigation. The page impersonates the professional networking platform to harvest credentials and session tokens, deploying a classic LinkedIn lure. No custom drainer kit artifacts have been extracted, but behavioral analysis confirms form submission to a remote endpoint matching known LinkedIn phishing infrastructure. The domain was registered through GitHub Pages on 2024-05-09 and serves content over a Let’s Encrypt SSL certificate, exhibiting low initial suspicion due to GitHub’s legitimate infrastructure abuse.
Technical indicators confirm elevated risk: VirusTotal currently scores the page 7/95 with zero vendor detections, indicating zero current coverage despite active phishing operations. Resolving to IP address 185.199.108.153 operated by Fastly, the domain is not flagged in Google Safe Browsing (GSB status: clean) and remains absent from major threat blocklists as of 2024-05-24. The GitHub Pages origin obscures hostile infrastructure, enabling prolonged availability while GitHub reviews and takedowns lag behind the campaign.
The phishing domain remains active as of 2024-05-24, with the threat actor rotating content to evade detection. GitHub has been notified via abuse channels, but no takedown has occurred within the first 24 hours, leaving users vulnerable. Remaining risk is assessed as high due to LinkedIn brand abuse, low vendor detection, and GitHub’s delayed response cycle. Users should avoid clicking links from unsolicited messages referencing “LinkedIn profile views” or “connection requests” and verify any login pages via LinkedIn’s official domain. Security teams are advised to block the resolved IP 185.199.108.153 at the perimeter and monitor for continued C2 traffic to the domain.
데이터 적용 범위12 recorded checks
네트워크 보안 인텔리전스
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| DNS4EU | dhruvi-patel15.github.io |
malicious | Sinkholed |
위협 대응 Pipeline
공개 차단 목록 상태
사용 기술 · 3 identified
Fastly is a cloud computing services provider. Fastly's cloud platform provides a content delivery network, Internet security services, load balancing, and video & streaming services.
www.fastly.com 신뢰도 100%VirusTotal 분석
사이트 성능 분석
Google PageSpeed Insights — mobile performance audit of dhruvi-patel15.github.io · checked May 1, 2026
증거 및 외부 보고서Independent lookups and source reports
Victim safety and official reportingImmediate actions and verified reporting channels
계정 자격 증명, 개인 정보 또는 결제 정보를 입력했거나 이 도메인에서 파일을 다운로드한 경우 즉시 조치를 취하세요. 다음은 사건을 신고하고 자신을 보호하는 데 도움이 되는 리소스입니다.
지역 당국에 신고하십시오
공식 사이버 범죄 연락처 또는 불만사항 초안 작성 →를 받으려면 국가를 선택하세요.