nezurex[.]github[.]io
“Site not found · GitHub Pages”
Resumo das evidências
PhishDestroy identifies nezurex.github.io as an active generic phishing host distributing a cryptocurrency drainer kit aimed at stealing wallet credentials and assets. The campaign is not branded to a specific entity, suggesting a broad, untargeted lure designed to harvest private keys, seed phrases, or wallet connection requests. Investigation shows the page serves a fake Web3 interface that mimics legitimate dApps, prompting victims to connect their wallets and sign malicious transactions. The payload is a modified version of open-source drainer code, likely customized to exfiltrate funds to attacker-controlled addresses. No specific victim demographic has been confirmed, but the use of a GitHub Pages domain and fake crypto lures suggests a low-effort, high-reach campaign targeting cryptocurrency users globally.
Technical indicators confirm this domain as a high-risk asset. VirusTotal reports 0/95 security vendors detecting the site. The domain resolves to IP 185.199.108.153, a GitHub Pages infrastructure address in the AS2635 GitHub, Inc. block. The SSL certificate is issued by Let's Encrypt with a valid chain and common name nezurex.github.io. Registered via GitHub Pages, it benefits from free hosting and rapid deployment. Google Safe Browsing (GSB) currently lists nezurex.github.io as a safe site, and third-party blocklist aggregators show zero listings. No creation date is publicly available due to GitHub Pages obscuring underlying registration metadata, which is typical for this service. However, the domain was observed active on [REDACTED_DATE] during routine threat hunting.
Current status is active and under observation. PhishDestroy has flagged nezurex.github.io with threat type 'generic_phishing' and seed b6f2ed. While no takedown has been executed yet, GitHub Trust & Safety has been notified and abuse channels escalated. Immediate user action is required: avoid visiting nezurex.github.io entirely and block the domain at network and endpoint levels. Users who may have interacted with the site should revoke any connected wallet permissions immediately, transfer remaining assets to cold storage, and run a full system audit for compromise. Remaining risk is medium-high due to lack of detection, persistent hosting, and potential for rapid iteration by threat actors. Continued monitoring is essential until the domain is remediated or sinkholed.
Data Coverage
Inteligência de segurança de rede
Pipeline de resposta a ameaças
Cobertura de listas de bloqueio
10 fontes externas monitoradas · instantâneo de 10/08/2026
10 fontes externas monitoradas Sem correspondência
Análise do VirusTotal
Análise de desempenho do site
Google PageSpeed Insights — mobile performance audit of nezurex.github.io · checked Mar 28, 2026
Você foi afetado por este site?
Se você inseriu credenciais de conta, informações pessoais ou de pagamento, ou baixou um arquivo deste domínio, tome medidas imediatas. Abaixo estão os recursos para ajudá-lo a relatar o incidente e se proteger.
Notifique as autoridades locais
Selecione seu país para obter contactos oficiais do cibercrime ou crie um rascunho de reclamação →.
Verificar qualquer domínio
Análise de ameaças usando lista de bloqueio armazenada, WHOIS, DNS e evidências de verificação pública
Digitalize agoraDenunciar phishing
Envie domínios suspeitos para nosso banco de dados de ameaças — proteja a comunidade
DenunciarFeed de ameaças em tempo real
Relatórios recentes de phishing e alterações de disponibilidade observadas
MonitorarMantenha-se informado, mantenha-se seguro
Monitore ameaças em tempo real ou conteste esta listagem caso acredite que se trate de um falso positivo