aliforouzand1987[.]github[.]io
“Site not found · GitHub Pages”
aliforouzand1987.github.io — Conteúdo indisponível. Resumo das evidências: VirusTotal 7/91 (ESET, Emsisoft, Fortinet, G-Data, Netcraft); PhishDestroy score 83/100. Registrador: GitHub.
A análise detalhada do PhishDestroy AI permanece em inglês para preservar o registro forense original.
On July 20 2026, aliforouzand1987.github.io was identified as a high‑risk generic phishing infrastructure. The domain is hosted on GitHub Pages and resolves to the IP address 185.199.108.153, which belongs to the GitHub, Inc. hosting network. Registration information shows the domain was created through GitHub, Inc., confirming that the attacker leveraged a legitimate cloud‑based code‑hosting service to obtain a free sub‑domain. The domain is currently listed on one security blocklist and has been blocked by the PhishDestroy feed, indicating that at least one external remediation service has taken action against it. VirusTotal analysis reports that 7 of 91 scanned security vendors flagged the domain, providing independent corroboration of malicious activity. No nameserver records were returned, which is consistent with the default GitHub Pages configuration that does not expose custom NS records.
The available evidence does not include a page title, SSL certificate details, HTTP response codes, or any observed payloads, so the exact phishing lure and target brand remain unverified. Likewise, the absence of additional blocklist entries or open‑source intelligence (e.g., OTX) limits the assessment of campaign scope. Nonetheless, the combination of a malicious sub‑domain, active blocklist status, and multiple vendor detections establishes a credible threat profile.
Defenders should add aliforouzand1987.github.io to URL filtering and DNS deny lists, monitor outbound traffic for connections to 185.199.108.153, and enforce web‑gateway policies that block content from known phishing feeds such as PhishDestroy. Continuous re‑scanning on VirusTotal and periodic checks of GitHub Pages sub‑domains are recommended to detect potential re‑use of the same hosting infrastructure.
Pipeline de resposta a ameaças
Status da lista de bloqueios pública
Tecnologias · 3 identified
Fastly is a cloud computing services provider. Fastly's cloud platform provides a content delivery network, Internet security services, load balancing, and video & streaming services.
www.fastly.com 100% de confiançaAnálise do VirusTotal
Análise de desempenho do site
Google PageSpeed Insights — mobile performance audit of aliforouzand1987.github.io · checked Jul 20, 2026
Evidências e relatórios externos
Você foi afetado por este site?
Se você inseriu credenciais de conta, informações pessoais ou de pagamento, ou baixou um arquivo deste domínio, tome medidas imediatas. Abaixo estão os recursos para ajudá-lo a relatar o incidente e se proteger.
Notifique as autoridades locais
Selecione seu país para obter contactos oficiais do cibercrime ou crie um rascunho de reclamação →.
Verificar qualquer domínio
Análise de ameaças usando lista de bloqueio armazenada, WHOIS, DNS e evidências de verificação pública
Digitalize agoraDenunciar phishing
Envie domínios suspeitos para nosso banco de dados de ameaças — proteja a comunidade
DenunciarFeed de ameaças em tempo real
Relatórios recentes de phishing e alterações de disponibilidade observadas
MonitorarMantenha-se informado, mantenha-se seguro
Monitore ameaças em tempo real ou conteste esta listagem caso acredite que se trate de um falso positivo