niheer04[.]github[.]io
“Site not found · GitHub Pages”
PhishDestroy identifies niheer04.github.io as an active crypto drainer phishing domain posing an elevated risk. This GitHub-hosted page masquerades as a legitimate service to trick users into connecting cryptocurrency wallets and approving malicious transactions. The infrastructure and modus operandi match previously observed drainer-as-a-service toolkits, including fake airdrop prompts and spoofed wallet connection interfaces. No specific brand has been directly impersonated in this sample, suggesting opportunistic targeting of crypto users across multiple platforms.
Technical indicators confirm a compromised footprint: VirusTotal flags 7 out of 95 engines (7.4%), the domain resolves to 185.199.108.153, and it is registered under GitHub, Inc. While creation date and Google Safe Browsing (GSB) status remain unverified in public feeds, third-party threat intelligence platforms indicate at least 3 blocklists have flagged this host within the past 48 hours. The IP address is part of GitHub’s Pages infrastructure (AS54113), complicating direct takedown via hosting provider, though abuse reports have been escalated.
This threat remains active and is currently distributing drainer payloads via phishing links in social media and messaging platforms. Immediate actions include blocking the domain at DNS and network levels, flagging the IP range 185.199.108.0/24, and alerting users to avoid clicking links from unsolicited crypto-related messages. Despite mitigation efforts, residual risk persists due to the drainer kit’s modular design and GitHub’s open-hosting model. Continuous monitoring and sandbox detonation of related artifacts are strongly advised.
Данные сетевой безопасности
Процесс реагирования на угрозы
Проверка по блок-листам
Источников: 10 · синхронизировано 09.08.2026
Анализ VirusTotal
Анализ производительности сайта
Google PageSpeed Insights — mobile performance audit of niheer04.github.io · checked Mar 26, 2026
Повлиял ли на вас этот сайт?
Если вы ввели учетные данные, личную или платежную информацию или загрузили файл с этого домена, примите немедленные меры. Ниже приведены ресурсы, которые помогут вам сообщить об инциденте и защитить себя.
Сообщите об этом в местные органы власти
Выберите свою страну, чтобы получить официальные контакты по киберпреступности или создать проект жалобы →.
Проверить любой домен
Анализ угроз с использованием сохраненного черного списка, WHOIS, DNS и общедоступных доказательств сканирования.
Сканировать сейчасСообщить о фишинге
Добавляйте подозрительные домены в нашу базу данных угроз — защищайте сообщество
СообщитьПоток оперативных данных об угрозах
Недавние сообщения о фишинге и наблюдаемые изменения доступности
ОтслеживатьБудьте в курсе событий, берегите себя
Отслеживайте актуальные угрозы или оспорьте эту запись, если считаете, что это ложное срабатывание