somyaa1207[.]github[.]io
“Site not found · GitHub Pages”
Resumo das evidências
PhishDestroy identifies somyaa1207.github.io as a live crypto drainer impersonating a cryptocurrency wallet login portal. This GitHub-hosted domain attempts to trick users into connecting malicious wallets to drain funds by mimicking legitimate authentication flows. Security researchers observed suspicious JavaScript payloads embedded in the page that intercept wallet connection requests and trigger unauthorized transactions. The domain leverages GitHub Pages' trusted infrastructure to evade traditional blocklists, making it particularly deceptive for crypto users unfamiliar with these tactics. This domain was flagged with a VirusTotal detection ratio of 6/95 engines at time of writing, indicating it remains undetected by mainstream antivirus solutions. It resolves to IP 185.199.108.153 through Let's Encrypt SSL certificates, masking malicious activity under legitimate encryption. Registered through GitHub's infrastructure, the domain exhibits characteristics of a newly weaponized GitHub Pages instance, highlighting threat actors' preference for abusing reputable platforms. While specific creation dates weren't provided in available intelligence, the combination of zero detections and active hosting suggests recent deployment as part of ongoing crypto scam campaigns. Users should immediately stop any interaction with somyaa1207.github.io, especially wallet connection prompts. Do not enter credentials or connect wallets to this domain under any circumstances. If visited accidentally, disconnect all wallet connections in your browser's active sessions and revoke any approved permissions through your wallet's connection management interface. Report the domain to PhishDestroy for verification and consider installing crypto-specific browser extensions that detect drainer domains in real-time. Always verify URLs through official channels before engaging with crypto services, and treat GitHub-hosted login pages as suspicious unless confirmed through primary contact methods.
Data Coverage
Inteligência de segurança de rede
Pipeline de resposta a ameaças
Cobertura de listas de bloqueio
10 fontes externas monitoradas · instantâneo de 10/08/2026
10 fontes externas monitoradas Sem correspondência
Análise do VirusTotal
Análise de desempenho do site
Google PageSpeed Insights — mobile performance audit of somyaa1207.github.io · checked Apr 3, 2026
Você foi afetado por este site?
Se você inseriu credenciais de conta, informações pessoais ou de pagamento, ou baixou um arquivo deste domínio, tome medidas imediatas. Abaixo estão os recursos para ajudá-lo a relatar o incidente e se proteger.
Notifique as autoridades locais
Selecione seu país para obter contactos oficiais do cibercrime ou crie um rascunho de reclamação →.
Verificar qualquer domínio
Análise de ameaças usando lista de bloqueio armazenada, WHOIS, DNS e evidências de verificação pública
Digitalize agoraDenunciar phishing
Envie domínios suspeitos para nosso banco de dados de ameaças — proteja a comunidade
DenunciarFeed de ameaças em tempo real
Relatórios recentes de phishing e alterações de disponibilidade observadas
MonitorarMantenha-se informado, mantenha-se seguro
Monitore ameaças em tempo real ou conteste esta listagem caso acredite que se trate de um falso positivo