yashisahay[.]github[.]io
“Site not found · GitHub Pages”
Resumo das evidências
This domain, yashisahay.github.io, is actively flagged as a credential theft scam designed to harvest login credentials, financial details, or other sensitive information from unsuspecting visitors. Unlike generic phishing pages, credential theft sites often mimic legitimate login portals for banks, email providers, or corporate systems, tricking users into submitting their usernames and passwords. The domain may also deploy keyloggers or session hijacking scripts to capture data in real time, even if the visible page appears inactive or returns a 'Site not found' error. Given its high-risk classification and active status, interaction with this domain poses a direct threat to personal and organizational security. Analysis indicates this domain is hosted on GitHub Pages infrastructure, resolving to the IP address 185.199.108.153, a known hosting range for both legitimate and malicious content. The domain was registered through GitHub, Inc. on April 08, 2026, though the creation date appears anomalous, suggesting potential manipulation or misconfiguration. The SSL certificate is issued by Let's Encrypt, a common tool used by threat actors to lend false legitimacy to malicious sites. Security vendors on VirusTotal flag this domain as malicious, with 15 out of 95 engines detecting it as a threat. Additionally, the domain appears on two independent security blocklists, reinforcing its classification as a high-risk credential theft operation. If you have visited yashisahay.github.io or entered any credentials on a page resembling this domain, immediate action is required to mitigate potential compromise. First, disconnect the affected device from the network to prevent further data exfiltration. Change passwords for all accounts accessed from the device, prioritizing email, financial, and administrative systems. Enable multi-factor authentication where available to add an additional layer of security. Monitor accounts for unauthorized activity, such as logins from unfamiliar locations or devices. If financial information was entered, contact your bank or payment provider to report potential fraud and request transaction monitoring. Finally, scan the device with updated security software to detect and remove any malware or persistent threats. Given the domain's active status and high-risk classification, users should remain vigilant for follow-up phishing attempts or social engineering attacks.
Data Coverage
Inteligência de segurança de rede
Pipeline de resposta a ameaças
Cobertura de listas de bloqueio
10 fontes externas monitoradas · instantâneo de 11/08/2026
10 fontes externas monitoradas Sem correspondência
Inteligência de Domínios
Detalhes técnicosDNS, nomes TLS e datas
Análise do VirusTotal
Análise de desempenho do site
Google PageSpeed Insights — mobile performance audit of yashisahay.github.io · checked Apr 8, 2026
Você foi afetado por este site?
Se você inseriu credenciais de conta, informações pessoais ou de pagamento, ou baixou um arquivo deste domínio, tome medidas imediatas. Abaixo estão os recursos para ajudá-lo a relatar o incidente e se proteger.
Notifique as autoridades locais
Selecione seu país para obter contactos oficiais do cibercrime ou crie um rascunho de reclamação →.
Verificar qualquer domínio
Análise de ameaças usando lista de bloqueio armazenada, WHOIS, DNS e evidências de verificação pública
Digitalize agoraDenunciar phishing
Envie domínios suspeitos para nosso banco de dados de ameaças — proteja a comunidade
DenunciarFeed de ameaças em tempo real
Relatórios recentes de phishing e alterações de disponibilidade observadas
MonitorarMantenha-se informado, mantenha-se seguro
Monitore ameaças em tempo real ou conteste esta listagem caso acredite que se trate de um falso positivo