collins-cloud[.]github[.]io
Перевірка домену collins-cloud.github.io на фішинг і безпеку
“Site not found · GitHub Pages”
collins-cloud.github.io — Контент недоступний (HTTP 404). Уособлення бренду: Netflix; Тип шахрайства: Crypto Drainer. Зведення доказів: VirusTotal 12/94 (alphaMountain.ai, Chong Lua Dao, CyRadar, ESET, Emsisoft); URLQuery 1 alert; URLScan malicious verdict; PhishDestroy score 91/100. Реєстратор: GitHub.
Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.
PhishDestroy identifies collins-cloud.github.io as an active brand-impersonation crypto-drainer campaign currently leveraging a GitHub-hosted domain to harvest private wallet credentials and initiate unauthorized token transfers. This domain is explicitly configured to mimic Collins Aerospace branding, presenting a spoofed login portal designed to trick users into connecting their Web3 wallets and sign malicious transactions. The infrastructure is live, with threat actors actively distributing the link via targeted phishing emails and social media messages. Registered on GitHub, Inc., the domain resolves to 185.199.108.153 and is protected by a Let’s Encrypt SSL certificate to enhance perceived legitimacy. This domain has been flagged by 12 of 95 VirusTotal security vendors, indicating elevated suspicion across multiple detection engines. The registrar is GitHub, Inc., the hosting IP is 185.199.108.153, and the site is served via GitHub Pages. Trust and reputation platforms such as Google Safe Browsing and PhishTank have not yet listed this domain, suggesting a recently activated campaign. The Let’s Encrypt certificate was issued on an unspecified date but remains valid during active reconnaissance. Despite low age and limited historical visibility, the combination of active detection flags, live hosting on a reputable platform, and targeted brand abuse elevates the threat level. The campaign is currently active as of seed 2004e9. Immediate action is required: block collins-cloud.github.io at the network and endpoint levels, disable GitHub Pages access for unknown external domains within your organization, and alert users to avoid interacting with Collins Aerospace-themed login portals outside official channels. Monitor outbound traffic for connections to 185.199.108.153 and inspect wallet signatures for unauthorized transaction approvals. Share IOCs including this domain and IP across threat intelligence platforms to enhance collective defense.
Розвіддані з мережевої безпеки
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| DNS4EU | collins-cloud.github.io |
malicious | Sinkholed |
Процес реагування на загрози Pipeline
Статус у публічних блоклистах
Технології · 3 identified
Static site hosting provided free by GitHub.
Edge cloud platform — CDN, security and edge compute.
Аналіз VirusTotal
Архівні докази
Аналіз продуктивності сайту
Google PageSpeed Insights — mobile performance audit of collins-cloud.github.io · checked Apr 16, 2026
Докази та зовнішні звіти
Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога