mbalimasango-hue[.]github[.]io
mbalimasango-hue.github.io için kimlik avı ve güvenlik kontrolü
“Adobe PDF Online”
mbalimasango-hue.github.io — İçerik kullanılamıyor (HTTP 404). Marka kimliğine bürünme: Adobe; Dolandırıcılık türü: Generic Phishing. Kanıt özeti: VirusTotal 6/91 (Emsisoft, Forcepoint ThreatSeeker, G-Data, Gridinsoft, Netcraft); URLScan malicious verdict; PhishDestroy score 68/100. Kayıt kuruluşu: GitHub.
Özgün adli kaydı korumak için aşağıdaki ayrıntılı PhishDestroy AI analizi İngilizce bırakılmıştır.
This domain, mbalimasango-hue.github.io, is flagged as a confirmed phishing site specializing in brand impersonation targeting Adobe PDF Online users. Analysis indicates the threat actor has deployed a fraudulent portal mimicking legitimate Adobe document services, likely designed to harvest user credentials or distribute malicious payloads under the guise of PDF file access. The page title explicitly reads Adobe PDF Online, reinforcing the social engineering tactic to deceive visitors into believing they are interacting with an official Adobe service. No direct evidence of a crypto drainer kit or payment skimming infrastructure was observed, though credential theft remains the primary objective given the context and page design. Infrastructure analysis reveals multiple concrete technical indicators supporting the phishing classification. The domain is registered through GitHub, Inc. and resolves to the IP address 185.199.109.153, a known hosting range for GitHub Pages. Security vendor detections on VirusTotal stand at 6 out of 95, with the SSL certificate issued by Let's Encrypt under the YR2 intermediate. The domain appears on one security blocklist, though it remains unlisted in Google Safe Browsing at the time of assessment. Creation metadata is obscured due to GitHub's hosting model, but the active deployment and lack of legitimate content confirm malicious intent. The site remains active and poses a high risk to end users, particularly those accustomed to cloud-based PDF services. Immediate response actions include blacklisting the domain across enterprise security gateways, blocking the IP 185.199.109.153 at the network perimeter, and alerting users to the specific Adobe PDF Online impersonation tactic. Remaining risk stems from the domain's continued operation under GitHub's infrastructure, which may delay takedown due to hosting policies. Users are advised to verify domain authenticity before entering credentials and to cross-check SSL certificates for inconsistencies. Organizations should monitor for credential reuse attempts following exposure to this phishing portal.
Tehdit Müdahale Pipeline
Genel Engelleme Listesi Durumu
Teknolojiler · 3 identified
Fastly is a cloud computing services provider. Fastly's cloud platform provides a content delivery network, Internet security services, load balancing, and video & streaming services.
www.fastly.com %100 güvenVirusTotal Analizi
Kanıtlar ve Dış Raporlar
Bu Siteden Etkilendiniz mi?
Hesap kimlik bilgilerini, kişisel bilgileri veya ödeme bilgilerini girdiyseniz ya da bu alan adından bir dosya indirdiyseniz hemen harekete geçin. Aşağıda olayı bildirmenize ve kendinizi korumanıza yardımcı olacak kaynaklar bulunmaktadır.
Yerel Yetkililere Bildirin
resmi siber suç iletişim bilgileri veya şikayet taslağı oluştur → almak için ülkenizi seçin.
Herhangi Bir Alan Adını Kontrol Et
Saklanan engelleme listesi, WHOIS, DNS ve genel tarama kanıtlarını kullanarak tehdit analizi
Şimdi TaraOltalama Olayını Bildir
Şüpheli alan adlarını tehdit veritabanımıza bildirin — topluluğu koruyun
BildirCanlı Tehdit Akışı
Son kimlik avı raporları ve gözlemlenen kullanılabilirlik değişiklikleri
İzleGelişmelerden Haberdar Olun, Güvende Kalın
Canlı tehditleri izleyin veya bunun yanlış bir uyarı olduğunu düşünüyorsanız bu kayda itiraz edin