pranavswaroopvarma[.]github[.]io
“Site not found · GitHub Pages”
PhishDestroy identifies the domain pranavswaroopvarma.github.io as an active crypto drainer phishing host engaged in credential theft and wallet draining operations. The site masquerades under a legitimate GitHub Pages subdomain while deploying malicious scripts designed to exfiltrate private keys, mnemonic phrases, or seed phrases from unsuspecting cryptocurrency users. No specific brand impersonation was detected in the available intelligence, suggesting a standalone phishing campaign targeting individual users rather than a corporate entity. The infrastructure appears optimized for rapid deployment and evasion, with a lightweight landing page likely serving as a gateway to a malicious drainer kit hosted on the same server or via linked external domains.
Technical analysis reveals this domain resolves to IP 185.199.108.153 and is registered through GitHub, Inc., leveraging the trusted GitHub Pages service to lend false legitimacy. Security vendor detection stands at 15 out of 95 on VirusTotal, indicating moderate but not universal recognition of the threat. The domain holds a valid SSL certificate issued by Let's Encrypt, which may help bypass browser warnings. While the exact creation date is not provided, the active status and fresh detection patterns suggest recent deployment. The domain has not been listed on Google Safe Browsing (GSB) as of this report, and blocklist counts remain unverified in public feeds. These factors combine to create an elevated risk profile, particularly for users interacting with crypto platforms or visiting finance-related content.
As of current assessment, the domain remains active and poses an ongoing threat to cryptocurrency users. Immediate actions include blocking the domain and IP at the network perimeter, updating endpoint protection rules, and warning end users to avoid visiting the site or interacting with any associated content. The risk level remains elevated due to the domain's use of a reputable hosting platform, valid SSL, and partial detection coverage. Users should verify all crypto-related domains via official channels and never enter seed phrases or private keys on untrusted pages. While GitHub has been notified previously in similar cases, proactive monitoring and user education are critical to mitigate further compromise. Remaining risk includes potential evolution into brand impersonation or expansion via subdomains, warranting continuous threat intelligence review.
Inteligência de segurança de rede
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| DNS4EU | pranavswaroopvarma.github.io |
malicious | Sinkholed |
Pipeline de resposta a ameaças
Cobertura de listas de bloqueio
10 fontes externas monitoradas · instantâneo de 10/08/2026
Análise do VirusTotal
Análise de desempenho do site
Google PageSpeed Insights — mobile performance audit of pranavswaroopvarma.github.io · checked Apr 16, 2026
Você foi afetado por este site?
Se você inseriu credenciais de conta, informações pessoais ou de pagamento, ou baixou um arquivo deste domínio, tome medidas imediatas. Abaixo estão os recursos para ajudá-lo a relatar o incidente e se proteger.
Notifique as autoridades locais
Selecione seu país para obter contactos oficiais do cibercrime ou crie um rascunho de reclamação →.
Verificar qualquer domínio
Análise de ameaças usando lista de bloqueio armazenada, WHOIS, DNS e evidências de verificação pública
Digitalize agoraDenunciar phishing
Envie domínios suspeitos para nosso banco de dados de ameaças — proteja a comunidade
DenunciarFeed de ameaças em tempo real
Relatórios recentes de phishing e alterações de disponibilidade observadas
MonitorarMantenha-se informado, mantenha-se seguro
Monitore ameaças em tempo real ou conteste esta listagem caso acredite que se trate de um falso positivo