nh638720-cmd[.]github[.]io
Verificação de phishing e segurança de nh638720-cmd.github.io
“nh638720-cmd.github.io”
nh638720-cmd.github.io — Conteúdo indisponível (HTTP 404). Tipo de golpe: Generic Phishing. Resumo das evidências: VirusTotal 7/91 (Emsisoft, G-Data, Gridinsoft, Netcraft, Sophos); PhishDestroy score 71/100. Registrador: GitHub.
A análise detalhada do PhishDestroy AI permanece em inglês para preservar o registro forense original.
This domain, nh638720-cmd.github.io, is an active phishing site designed to harvest user credentials through deceptive login portals. Analysis indicates the site mimics legitimate authentication pages, tricking visitors into entering sensitive information such as usernames, passwords, or other personal data. The threat primarily targets individuals who may believe they are accessing a trusted service, only to have their credentials stolen and potentially used for unauthorized account access or further malicious activity. Infrastructure analysis reveals the domain is hosted on GitHub Pages, a legitimate service often abused for phishing due to its free hosting and SSL certificates. The site resolves to the IP address 185.199.110.153, associated with Fastly, Inc. (AS54113) in the United States. It employs a Let's Encrypt SSL certificate (R12), which provides an illusion of security while remaining fully functional for malicious purposes. As of the latest scan, 7 out of 95 security vendors on VirusTotal have flagged the domain as malicious, confirming its phishing nature. The domain appears on at least one security blocklist and is currently marked as active, with no indication of takedown efforts. If you have visited nh638720-cmd.github.io or entered any information on the site, immediate action is required. First, change the passwords for any accounts that may have been exposed, prioritizing email, financial, and work-related credentials. Enable multi-factor authentication (MFA) on all critical accounts to mitigate the risk of unauthorized access. Monitor your accounts for suspicious activity, such as unrecognized logins or transactions, and report any anomalies to the respective service providers. Additionally, scan your device for malware using updated security tools to ensure no secondary infections were introduced. Avoid interacting with the domain or any links associated with it, and report the phishing site to GitHub for takedown by submitting abuse reports through their official channels.
Pipeline de resposta a ameaças
Status da lista de bloqueios pública
Tecnologias · 3 identified
Fastly is a cloud computing services provider. Fastly's cloud platform provides a content delivery network, Internet security services, load balancing, and video & streaming services.
www.fastly.com 100% de confiançaAnálise do VirusTotal
Evidências e relatórios externos
Você foi afetado por este site?
Se você inseriu credenciais de conta, informações pessoais ou de pagamento, ou baixou um arquivo deste domínio, tome medidas imediatas. Abaixo estão os recursos para ajudá-lo a relatar o incidente e se proteger.
Notifique as autoridades locais
Selecione seu país para obter contactos oficiais do cibercrime ou crie um rascunho de reclamação →.
Verificar qualquer domínio
Análise de ameaças usando lista de bloqueio armazenada, WHOIS, DNS e evidências de verificação pública
Digitalize agoraDenunciar phishing
Envie domínios suspeitos para nosso banco de dados de ameaças — proteja a comunidade
DenunciarFeed de ameaças em tempo real
Relatórios recentes de phishing e alterações de disponibilidade observadas
MonitorarMantenha-se informado, mantenha-se seguro
Monitore ameaças em tempo real ou conteste esta listagem caso acredite que se trate de um falso positivo