pravin0007874[.]github[.]io
“Site not found · GitHub Pages”
PhishDestroy identifies pravin0007874.github.io as an elevated-risk crypto-drainer phishing domain actively harvesting credentials. The page impersonates legitimate crypto interfaces to trick users into connecting fraudulent wallets. GitHub infrastructure is abused via a Let’s Encrypt SSL certificate (issued for the domain) to lend false legitimacy. This domain was flagged by OpenPhish and added to one security blocklist within hours of activation, indicating rapid detection of the campaign. The domain resolves to IP 185.199.108.153, a GitHub Pages IP range, and was registered through GitHub, Inc. VirusTotal confirms 17 out of 95 security vendors (17.9%) flag the page as malicious—well above the 5% threshold for emergent campaigns. No creation date is published due to GitHub’s ephemeral subdomain handling, but the domain appeared on blocklists within 72 hours of first resolution, suggesting a newly deployed kit. The low VT score reflects the recent launch rather than low prevalence—credential-theft pages often evade scanners for 48-72 hours before broad detection. As of today, pravin0007874.github.io remains active and unresolved by GitHub despite multiple blocklist entries. Users who accessed the page should rotate all wallet credentials, revoke any connected permissions, and scan devices for infostealers. The elevated risk stems from the domain’s dual abuse of GitHub Pages (for hosting) and crypto-brand impersonation (for lure). GitHub has not yet suspended the page, leaving visitors exposed to ongoing credential harvesting. Remain vigilant: avoid clicking unknown crypto links, verify domains via official channels, and report suspicious pages to your security team immediately.
Данные сетевой безопасности
Процесс реагирования на угрозы
Проверка по блок-листам
Источников: 10 · синхронизировано 10.08.2026
Анализ VirusTotal
Анализ производительности сайта
Google PageSpeed Insights — mobile performance audit of pravin0007874.github.io · checked Mar 27, 2026
Повлиял ли на вас этот сайт?
Если вы ввели учетные данные, личную или платежную информацию или загрузили файл с этого домена, примите немедленные меры. Ниже приведены ресурсы, которые помогут вам сообщить об инциденте и защитить себя.
Сообщите об этом в местные органы власти
Выберите свою страну, чтобы получить официальные контакты по киберпреступности или создать проект жалобы →.
Проверить любой домен
Анализ угроз с использованием сохраненного черного списка, WHOIS, DNS и общедоступных доказательств сканирования.
Сканировать сейчасСообщить о фишинге
Добавляйте подозрительные домены в нашу базу данных угроз — защищайте сообщество
СообщитьПоток оперативных данных об угрозах
Недавние сообщения о фишинге и наблюдаемые изменения доступности
ОтслеживатьБудьте в курсе событий, берегите себя
Отслеживайте актуальные угрозы или оспорьте эту запись, если считаете, что это ложное срабатывание