mbalimasango-hue[.]github[.]io
mbalimasango-hue.github.io 피싱 및 보안 점검
“Adobe PDF Online”
mbalimasango-hue.github.io — 콘텐츠를 사용할 수 없음 (HTTP 404). 브랜드 사칭: Adobe; 사기 유형: Generic Phishing. 증거 요약: VirusTotal 6/91 (Emsisoft, Forcepoint ThreatSeeker, G-Data, Gridinsoft, Netcraft); URLScan malicious verdict; PhishDestroy score 68/100. 등록기관: GitHub.
원본 포렌식 기록을 보존하기 위해 아래의 상세 PhishDestroy AI 분석은 영어로 유지됩니다.
This domain, mbalimasango-hue.github.io, is flagged as a confirmed phishing site specializing in brand impersonation targeting Adobe PDF Online users. Analysis indicates the threat actor has deployed a fraudulent portal mimicking legitimate Adobe document services, likely designed to harvest user credentials or distribute malicious payloads under the guise of PDF file access. The page title explicitly reads Adobe PDF Online, reinforcing the social engineering tactic to deceive visitors into believing they are interacting with an official Adobe service. No direct evidence of a crypto drainer kit or payment skimming infrastructure was observed, though credential theft remains the primary objective given the context and page design. Infrastructure analysis reveals multiple concrete technical indicators supporting the phishing classification. The domain is registered through GitHub, Inc. and resolves to the IP address 185.199.109.153, a known hosting range for GitHub Pages. Security vendor detections on VirusTotal stand at 6 out of 95, with the SSL certificate issued by Let's Encrypt under the YR2 intermediate. The domain appears on one security blocklist, though it remains unlisted in Google Safe Browsing at the time of assessment. Creation metadata is obscured due to GitHub's hosting model, but the active deployment and lack of legitimate content confirm malicious intent. The site remains active and poses a high risk to end users, particularly those accustomed to cloud-based PDF services. Immediate response actions include blacklisting the domain across enterprise security gateways, blocking the IP 185.199.109.153 at the network perimeter, and alerting users to the specific Adobe PDF Online impersonation tactic. Remaining risk stems from the domain's continued operation under GitHub's infrastructure, which may delay takedown due to hosting policies. Users are advised to verify domain authenticity before entering credentials and to cross-check SSL certificates for inconsistencies. Organizations should monitor for credential reuse attempts following exposure to this phishing portal.
위협 대응 Pipeline
공개 차단 목록 상태
사용 기술 · 3 identified
Fastly is a cloud computing services provider. Fastly's cloud platform provides a content delivery network, Internet security services, load balancing, and video & streaming services.
www.fastly.com 신뢰도 100%VirusTotal 분석
증거 및 외부 보고서
이 사이트로 인해 영향을 받으셨나요?
계정 자격 증명, 개인 정보 또는 결제 정보를 입력했거나 이 도메인에서 파일을 다운로드한 경우 즉시 조치를 취하세요. 다음은 사건을 신고하고 자신을 보호하는 데 도움이 되는 리소스입니다.
지역 당국에 신고하십시오
공식 사이버 범죄 연락처 또는 불만사항 초안 작성 →를 받으려면 국가를 선택하세요.