zeustheking[.]github[.]io
“Spotify - Web Player:Music for everyone”
Observação armazenada
Contraste de títulos observado
Resumo das evidências
This domain is flagged as a high-risk credential theft operation targeting users of a major music streaming platform. Analysis indicates the site is designed to harvest login credentials by impersonating the Spotify Web Player interface, as evidenced by the page title "Spotify - Web Player: Music for everyone." The threat is classified as active and unresolved, with infrastructure analysis revealing multiple technical indicators of malicious intent. Infrastructure analysis reveals the domain is hosted on GitHub Pages, resolving to the IPv6 address 2606:50c0:8000::153, geolocated within the United States under AS54113 (Fastly, Inc.). The SSL certificate is issued by Let's Encrypt (R12), a common but not inherently malicious certificate authority. However, the domain is flagged by 6 out of 95 security vendors on VirusTotal, and it appears on at least one security blocklist. The registrar is GitHub, Inc., a platform frequently exploited for hosting phishing content due to its free and accessible nature. No creation date is provided, but the domain remains active and unmitigated as of this assessment. To mitigate the risk of credential theft, users are advised to verify the legitimacy of any login portal by cross-referencing the URL with the official domain of the service (e.g., spotify.com). Organizations should implement domain-based blocking for this address and monitor for similar impersonation attempts targeting their user base. Multi-factor authentication (MFA) should be enforced to reduce the impact of stolen credentials. Network administrators are encouraged to inspect logs for connections to 2606:50c0:8000::153 and correlate with any unauthorized access attempts. Security teams should prioritize awareness training to educate users on identifying fraudulent login pages, particularly those mimicking popular brands.
Data Coverage
Pipeline de resposta a ameaças
Cobertura de listas de bloqueio
10 fontes externas monitoradas · instantâneo de 12/08/2026
10 fontes externas monitoradas Sem correspondência
Tecnologias
3 tecnologias identificadas com alta confiança
Análise do VirusTotal
Você foi afetado por este site?
Se você inseriu credenciais de conta, informações pessoais ou de pagamento, ou baixou um arquivo deste domínio, tome medidas imediatas. Abaixo estão os recursos para ajudá-lo a relatar o incidente e se proteger.
Notifique as autoridades locais
Selecione seu país para obter contactos oficiais do cibercrime ou crie um rascunho de reclamação →.
Verificar qualquer domínio
Análise de ameaças usando lista de bloqueio armazenada, WHOIS, DNS e evidências de verificação pública
Digitalize agoraDenunciar phishing
Envie domínios suspeitos para nosso banco de dados de ameaças — proteja a comunidade
DenunciarFeed de ameaças em tempo real
Relatórios recentes de phishing e alterações de disponibilidade observadas
MonitorarMantenha-se informado, mantenha-se seguro
Monitore ameaças em tempo real ou conteste esta listagem caso acredite que se trate de um falso positivo