rashid-25[.]github[.]io
“Amazon”
Observação armazenada
Contraste de títulos observado
Resumo das evidências
This domain, rashid-25.github.io, is identified as a high-risk phishing site designed to harvest Amazon account credentials. The page mimics the official Amazon login interface, tricking users into entering sensitive information such as usernames, passwords, and payment details. Analysis indicates the site is actively targeting individuals through deceptive emails or advertisements that redirect to this fraudulent portal, potentially leading to unauthorized account access or financial fraud. Infrastructure analysis reveals the domain is hosted on GitHub Pages, registered through GitHub, Inc., and resolves to the IPv6 address 2606:50c0:8003::153, associated with AS54113 (Fastly, Inc.) in the United States. The SSL certificate is issued by Let's Encrypt (R12), a common choice for both legitimate and malicious sites. Detection metrics confirm its malicious nature: 5 out of 95 security vendors on VirusTotal flag the domain as phishing, and it appears on one security blocklist. Google Safe Browsing also classifies the site as phishing, reinforcing its fraudulent intent. If a user has visited rashid-25.github.io or entered credentials on the site, immediate action is required. First, change the Amazon account password using a secure device and enable multi-factor authentication if not already active. Review recent account activity for unauthorized transactions or modifications. Monitor linked financial accounts for suspicious charges and consider placing a fraud alert with credit bureaus. Users should also clear browser cache and cookies to remove any residual tracking elements. If credentials were reused across other platforms, update those passwords as well. Report the incident to the legitimate service provider and relevant cybersecurity authorities to aid in takedown efforts.
Data Coverage
Pipeline de resposta a ameaças
Cobertura de listas de bloqueio
10 fontes externas monitoradas · instantâneo de 11/08/2026
10 fontes externas monitoradas Sem correspondência
Tecnologias
3 tecnologias identificadas com alta confiança
Análise do VirusTotal
Você foi afetado por este site?
Se você inseriu credenciais de conta, informações pessoais ou de pagamento, ou baixou um arquivo deste domínio, tome medidas imediatas. Abaixo estão os recursos para ajudá-lo a relatar o incidente e se proteger.
Notifique as autoridades locais
Selecione seu país para obter contactos oficiais do cibercrime ou crie um rascunho de reclamação →.
Verificar qualquer domínio
Análise de ameaças usando lista de bloqueio armazenada, WHOIS, DNS e evidências de verificação pública
Digitalize agoraDenunciar phishing
Envie domínios suspeitos para nosso banco de dados de ameaças — proteja a comunidade
DenunciarFeed de ameaças em tempo real
Relatórios recentes de phishing e alterações de disponibilidade observadas
MonitorarMantenha-se informado, mantenha-se seguro
Monitore ameaças em tempo real ou conteste esta listagem caso acredite que se trate de um falso positivo