naveen478928[.]github[.]io
“naveen478928.github.io”
Observação armazenada
Contraste de títulos observado
Resumo das evidências
This domain, naveen478928.github.io, operates as a brand impersonation phishing site designed to deceive users of the Aave decentralized finance platform. The site mimics legitimate Aave interfaces, likely presenting fake login portals or transaction prompts to harvest credentials or cryptocurrency wallet details. Users who interact with the site risk unauthorized access to their accounts, financial theft, or deployment of crypto drainer malware, which automatically siphons funds from connected wallets. The threat is particularly severe for individuals unfamiliar with Aave’s official domains or security practices, as the impersonation may appear convincing at first glance. Analysis indicates the domain is hosted through GitHub Pages, a legitimate service often exploited for phishing due to its free hosting and SSL certificates. The site resolves to the IP address 185.199.110.153, associated with Fastly, Inc. (AS54113), a content delivery network frequently used to mask malicious infrastructure. As of the latest scan, 9 out of 95 security vendors on VirusTotal flag the domain as malicious, with detections including phishing and brand impersonation. The SSL certificate is issued by Let’s Encrypt (R12), a common certificate authority that does not validate the legitimacy of the site’s content. The domain appears on at least one security blocklist, and Google Safe Browsing has explicitly labeled it as a phishing threat. No legitimate registration details or creation date are publicly available, as the domain leverages GitHub’s infrastructure rather than a traditional registrar. Users who have visited naveen478928.github.io should immediately disconnect any connected wallets or devices from the internet to prevent further unauthorized access. If credentials or wallet details were entered, revoke all active sessions and reset passwords for associated accounts, prioritizing those linked to cryptocurrency or financial services. Scan the affected device using updated security tools to detect and remove any malware, particularly crypto drainers or keyloggers. Monitor all connected accounts for unauthorized transactions, and report the incident to the targeted platform (Aave) to assist in broader mitigation efforts. For future protection, verify domain authenticity by cross-referencing with official sources and enable multi-factor authentication on all critical accounts. Avoid interacting with unsolicited links, even if they appear to originate from trusted brands.
Data Coverage
Pipeline de resposta a ameaças
Cobertura de listas de bloqueio
10 fontes externas monitoradas · instantâneo de 11/08/2026
10 fontes externas monitoradas Sem correspondência
Tecnologias
3 tecnologias identificadas com alta confiança
Análise do VirusTotal
Você foi afetado por este site?
Se você inseriu credenciais de conta, informações pessoais ou de pagamento, ou baixou um arquivo deste domínio, tome medidas imediatas. Abaixo estão os recursos para ajudá-lo a relatar o incidente e se proteger.
Notifique as autoridades locais
Selecione seu país para obter contactos oficiais do cibercrime ou crie um rascunho de reclamação →.
Verificar qualquer domínio
Análise de ameaças usando lista de bloqueio armazenada, WHOIS, DNS e evidências de verificação pública
Digitalize agoraDenunciar phishing
Envie domínios suspeitos para nosso banco de dados de ameaças — proteja a comunidade
DenunciarFeed de ameaças em tempo real
Relatórios recentes de phishing e alterações de disponibilidade observadas
MonitorarMantenha-se informado, mantenha-se seguro
Monitore ameaças em tempo real ou conteste esta listagem caso acredite que se trate de um falso positivo