hieunbk765[.]github[.]io
“Site not found · GitHub Pages”
Resumo das evidências
PhishDestroy identifies hieunbk765.github.io as an active crypto drainer phishing domain designed to steal cryptocurrency wallet credentials and assets. The domain is configured to impersonate legitimate crypto platforms, luring victims with fake investment portals or wallet authentication pages. Security researchers have confirmed the presence of drainer scripts, such as clipboard hijackers and malicious wallet connection prompts, which exfiltrate private keys or initiate unauthorized transactions upon user interaction. This domain represents a high-risk threat to cryptocurrency users, particularly those engaging with decentralized finance (DeFi) or NFT platforms.
Technical analysis reveals this domain resolves to IP address 185.199.108.153 and is registered via GitHub, Inc., leveraging their Pages service to host malicious content under a seemingly legitimate subdomain. VirusTotal analysis shows 18 out of 95 security vendors flag this domain as malicious, with Google Safe Browsing classifying it under the SOCIAL_ENGINEERING category. The domain is protected by a Let's Encrypt SSL certificate, adding a false sense of legitimacy. Additionally, it appears on 1 security blocklist, including the OISD blocklist, though this coverage remains limited given the domain’s recent activation and GitHub-hosted infrastructure. The exact creation date is not publicly disclosed, but the combination of hosting provider, SSL certificate, and detection metrics suggests it is a recently deployed threat.
This domain remains active and poses a significant risk to users who may inadvertently visit the URL or interact with embedded content. PhishDestroy has flagged hieunbk765.github.io as a high-risk threat, and immediate caution is advised. Users are strongly encouraged to verify any suspicious URLs through PhishDestroy’s database before proceeding. While GitHub has not yet taken down this subdomain, the growing detection rate across security vendors may lead to future takedowns. However, the domain’s low blocklist presence highlights gaps in real-time threat intelligence dissemination. Remaining risk is high due to the domain’s active status, cryptocurrency-focused lures, and the potential for drainer kits to evolve or be replaced by similar threats hosted under GitHub’s Pages service.
Data Coverage
Inteligência de segurança de rede
Pipeline de resposta a ameaças
Cobertura de listas de bloqueio
10 fontes externas monitoradas · instantâneo de 11/08/2026
10 fontes externas monitoradas Sem correspondência
Análise do VirusTotal
Análise de desempenho do site
Google PageSpeed Insights — mobile performance audit of hieunbk765.github.io · checked Apr 10, 2026
Você foi afetado por este site?
Se você inseriu credenciais de conta, informações pessoais ou de pagamento, ou baixou um arquivo deste domínio, tome medidas imediatas. Abaixo estão os recursos para ajudá-lo a relatar o incidente e se proteger.
Notifique as autoridades locais
Selecione seu país para obter contactos oficiais do cibercrime ou crie um rascunho de reclamação →.
Verificar qualquer domínio
Análise de ameaças usando lista de bloqueio armazenada, WHOIS, DNS e evidências de verificação pública
Digitalize agoraDenunciar phishing
Envie domínios suspeitos para nosso banco de dados de ameaças — proteja a comunidade
DenunciarFeed de ameaças em tempo real
Relatórios recentes de phishing e alterações de disponibilidade observadas
MonitorarMantenha-se informado, mantenha-se seguro
Monitore ameaças em tempo real ou conteste esta listagem caso acredite que se trate de um falso positivo