MALICIOUS — CRITICAL
rembourse0055[.]github[.]io
PhishDestroy identifies rembourse0055.github.io as an active generic phishing domain operating a crypto drainer kit designed to harvest wallet credentials and facilitate unauthorized transfers.
- VirusTotal
- 15/94
- Blocklists
- No stored match
- Disponibilidade
- Conteúdo indisponível · HTTP 404
Do not enter credentials, seed phrases, payment details, or personal information on this domain.
Jump to section
rembourse0055.github.io — Conteúdo indisponível (HTTP 404). Tipo de golpe: Generic Phishing. Resumo das evidências: VirusTotal 15/94 (ADMINUSLabs, Criminal IP, alphaMountain.ai, BitDefender, Chong Lua Dao); PhishDestroy score 100/100. Registrador: GitHub.
A análise detalhada do PhishDestroy AI permanece em inglês para preservar o registro forense original.
Evidence Analysis
PhishDestroy identifies rembourse0055.github.io as an active generic phishing domain operating a crypto drainer kit designed to harvest wallet credentials and facilitate unauthorized transfers. The domain mimics legitimate remboursement platforms, deploying a fake login interface to trick users into surrendering private keys or seed phrases. Analysis of the infrastructure suggests the threat actor leverages GitHub Pages to host the malicious content, enabling rapid deployment and evasion of traditional detection mechanisms.
This domain resolves to IP address 185.199.108.153 and was registered through GitHub, Inc., utilizing a Let’s Encrypt SSL certificate to enhance legitimacy. According to VirusTotal, rembourse0055.github.io has not yet been flagged, maintaining a clean detection score of 15 out of 95 engines. It has been blocked by OISD and appears on one additional security blocklist, indicating early-stage threat exposure. The domain’s recent registration and low detection rate suggest it is currently being evaluated as part of a broader phishing campaign targeting cryptocurrency users.
As of this report, rembourse0055.github.io remains active with a status of under_investigation. OISD has taken initial blocking action; however, the domain continues to evade broader detection. Users are strongly advised to avoid interacting with the site and to verify any suspicious links using PhishDestroy’s real-time lookup tool. While the immediate risk is elevated due to active hosting and minimal flagging, ongoing monitoring and community reporting are critical to mitigate further compromise.
Cobertura dos dados12 recorded checks
Inteligência de segurança de rede
Pipeline de resposta a ameaças
Status da lista de bloqueios pública
Análise do VirusTotal
Análise de desempenho do site
Google PageSpeed Insights — mobile performance audit of rembourse0055.github.io · checked Apr 6, 2026
Evidências e relatórios externosIndependent lookups and source reports
Victim safety and official reportingImmediate actions and verified reporting channels
Se você inseriu credenciais de conta, informações pessoais ou de pagamento, ou baixou um arquivo deste domínio, tome medidas imediatas. Abaixo estão os recursos para ajudá-lo a relatar o incidente e se proteger.
Notifique as autoridades locais
Selecione seu país para obter contactos oficiais do cibercrime ou crie um rascunho de reclamação →.