sandeepkumarnayak7[.]github[.]io
“Amazon Clone”
Kaydedilmiş gözlem
Gözlemlenen başlık farkı
Kanıt özeti
This domain, sandeepkumarnayak7.github.io, is actively engaged in credential harvesting targeting GitHub users. Analysis indicates the site presents a fraudulent GitHub login interface designed to capture usernames, passwords, and potentially two-factor authentication codes. The threat actor appears to be exploiting GitHub Pages hosting to lend legitimacy to the phishing attempt, a tactic observed in multiple recent campaigns leveraging free hosting services for malicious purposes. Infrastructure analysis reveals the domain resolves to 185.199.109.153, an IP address assigned to Fastly, Inc. (AS54113) and commonly associated with GitHub Pages. The domain is registered through GitHub, Inc. and uses a Let's Encrypt SSL certificate (YR2). As of the latest scan, 9 out of 95 security vendors on VirusTotal flag this domain as malicious. The domain appears on one security blocklist, though this number may underrepresent its actual detection rate due to delays in blocklist propagation. The GitHub Pages subdomain structure suggests the threat actor created a legitimate GitHub account to host the phishing content, which complicates takedown efforts. Users who have visited sandeepkumarnayak7.github.io should immediately revoke any entered credentials and enable multi-factor authentication on their GitHub accounts if not already active. Monitor account activity for unauthorized access or repository modifications, as compromised credentials may be used to distribute malware or conduct further phishing operations. Clear browser cache and stored credentials for the domain, as some variants employ persistent storage techniques to maintain access. Organizations should add this domain and its resolving IP to internal blocklists and consider implementing network-level protections to prevent access to GitHub Pages subdomains not explicitly whitelisted for business use. Given the domain's continued activity, assume any credentials entered have been compromised and act accordingly.
Data Coverage
Tehdit Müdahale Pipeline
Engelleme listesi kapsamı
10 izlenen harici kaynak · kayıtlı anlık görüntü 11.08.2026
Teknolojiler
3 yüksek güvenli teknoloji belirlendi
VirusTotal Analizi
Bu Siteden Etkilendiniz mi?
Hesap kimlik bilgilerini, kişisel bilgileri veya ödeme bilgilerini girdiyseniz ya da bu alan adından bir dosya indirdiyseniz hemen harekete geçin. Aşağıda olayı bildirmenize ve kendinizi korumanıza yardımcı olacak kaynaklar bulunmaktadır.
Yerel Yetkililere Bildirin
resmi siber suç iletişim bilgileri veya şikayet taslağı oluştur → almak için ülkenizi seçin.
Herhangi Bir Alan Adını Kontrol Et
Saklanan engelleme listesi, WHOIS, DNS ve genel tarama kanıtlarını kullanarak tehdit analizi
Şimdi TaraOltalama Olayını Bildir
Şüpheli alan adlarını tehdit veritabanımıza bildirin — topluluğu koruyun
BildirCanlı Tehdit Akışı
Son kimlik avı raporları ve gözlemlenen kullanılabilirlik değişiklikleri
İzleGelişmelerden Haberdar Olun, Güvende Kalın
Canlı tehditleri izleyin veya bunun yanlış bir uyarı olduğunu düşünüyorsanız bu kayda itiraz edin