MALICIOUS — CRITICAL
abdullahzaheer147[.]github[.]io
PhishDestroy identifies abdullahzaheer147.github.io as an active credential phishing domain posing as a fake login page to harvest user credentials.
- VirusTotal
- 17/94
- Blocklists
- No stored match
- Disponibilidade
- Conteúdo indisponível · HTTP 404
Do not enter credentials, seed phrases, payment details, or personal information on this domain.
Jump to section
abdullahzaheer147.github.io — Conteúdo indisponível (HTTP 404). Representação da marca: Netflix; Tipo de golpe: Credential Phishing. Resumo das evidências: VirusTotal 17/94 (ADMINUSLabs, Criminal IP, alphaMountain.ai, BitDefender, CyRadar); URLScan malicious verdict; Google Safe Browsing flagged; PhishDestroy score 100/100. Registrador: GitHub.
A análise detalhada do PhishDestroy AI permanece em inglês para preservar o registro forense original.
Evidence Analysis
PhishDestroy identifies abdullahzaheer147.github.io as an active credential phishing domain posing as a fake login page to harvest user credentials. This GitHub-hosted page leverages social engineering tactics to trick visitors into entering sensitive information, including passwords or payment details, under false pretenses. With 17 out of 95 security vendors flagging the domain and OpenPhish already blocking access, the threat is imminent and should be treated with high urgency. The domain’s association with social engineering campaigns, as confirmed by Google Safe Browsing’s SOCIAL_ENGINEERING classification, underscores its malicious intent and operational status. This domain resolves to IP address 185.199.108.153 and is hosted through GitHub, Inc., which has not suspended the repository despite multiple flaggings. Its SSL certificate, issued by Let’s Encrypt, provides a false sense of security by enabling HTTPS encryption, a common tactic to deceive users into trusting the site. The domain is currently listed on one security blocklist and continues to evade takedown efforts, suggesting persistent availability. Despite GitHub’s legitimate infrastructure, the misuse of their platform for phishing underscores the sophistication of modern credential harvesting campaigns, which exploit trusted domains to bypass traditional defenses. Users encountering this domain must avoid entering any personal or financial information, as the site is designed to capture input and transmit it to attackers. Immediately clear browser cache and cookies if accidentally interacted with, and scan devices for malware using updated antivirus tools. Report the domain to your email provider, browser, and platforms like OpenPhish or Google Safe Browsing to aid in its rapid deactivation. Always verify URLs manually before entering credentials, and use multi-factor authentication (MFA) wherever possible to mitigate the impact of credential theft. This threat highlights the importance of skepticism toward unsolicited links, even when hosted on reputable services like GitHub.
Cobertura dos dados12 recorded checks
Inteligência de segurança de rede
Pipeline de resposta a ameaças
Status da lista de bloqueios pública
Análise do VirusTotal
Análise de desempenho do site
Google PageSpeed Insights — mobile performance audit of abdullahzaheer147.github.io · checked Apr 2, 2026
Evidências e relatórios externosIndependent lookups and source reports
Victim safety and official reportingImmediate actions and verified reporting channels
Se você inseriu credenciais de conta, informações pessoais ou de pagamento, ou baixou um arquivo deste domínio, tome medidas imediatas. Abaixo estão os recursos para ajudá-lo a relatar o incidente e se proteger.
Notifique as autoridades locais
Selecione seu país para obter contactos oficiais do cibercrime ou crie um rascunho de reclamação →.