Перейти до звіту про безпеку
Checked 09.08.2026 Ref D70CFB5D

MALICIOUS — CRITICAL

vishnudas18[.]github[.]io

PhishDestroy identifies vishnudas18.github.io as an active crypto drainer phishing domain posing as a fraudulent cryptocurrency platform.

83/100 evidence score · Critical
VirusTotal
11/92
Blocklists
No stored match
Доступність
Контент недоступний · HTTP 404
Report / Add Evidence Appeal this listing
2026-05-14 16:09 UTCКонтент недоступний · HTTP 404

Do not enter credentials, seed phrases, payment details, or personal information on this domain.

⚠️
Цей домен було позначено як шкідливий
Системи безпеки повідомляють про виявлення: 11. Будьте дуже обережні — не вводьте облікові дані чи особисту інформацію.
Jump to section
Огляд звіту

vishnudas18.github.io — Контент недоступний (HTTP 404). Тип шахрайства: Generic Phishing. Зведення доказів: VirusTotal 11/92 (ADMINUSLabs, Criminal IP, alphaMountain.ai, BitDefender, Emsisoft); URLQuery 1 alert; PhishDestroy score 83/100. Реєстратор: GitHub.

Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.

Evidence Analysis

Ref D70CFB5D

PhishDestroy identifies vishnudas18.github.io as an active crypto drainer phishing domain posing as a fraudulent cryptocurrency platform. The site leverages GitHub Pages hosting to impersonate legitimate services, deploying malicious JavaScript to siphon cryptocurrency funds from unsuspecting users. The threat actor behind this domain employs deceptive tactics, including fake login portals and fraudulent transaction interfaces, to trick users into connecting their digital wallets and authorizing unauthorized transfers.

This domain resolves to IP address 185.199.108.153 and is registered through GitHub, Inc., utilizing a Let's Encrypt SSL certificate to appear legitimate. PhishDestroy's forensic analysis reveals that this domain was flagged by 10 out of 95 security vendors on VirusTotal, indicating a significant but not universal detection rate. The domain's infrastructure is hosted on GitHub's Pages service, which has been exploited by threat actors to host phishing and malicious content. While the exact creation date is not provided, the domain's recent flagging suggests it is part of an ongoing campaign rather than a long-established operation.

vishnudas18.github.io remains an active threat as of the latest assessment, with no immediate signs of takedown. Users are strongly advised to avoid interacting with this domain and to verify its status on PhishDestroy before taking any further action. The elevated risk level and partial detection by security vendors highlight the need for caution when encountering this domain. While GitHub's infrastructure is not inherently malicious, its misuse by threat actors underscores the importance of verifying URLs and using trusted security tools to mitigate risks. The remaining risk is elevated due to the domain's active status and the potential for continued exploitation in phishing campaigns.

VirusTotal
VirusTotal
11 det.
URLQuery
URLQuery
1 threat alert
URLScan
URLScan
Сертифікат TLS
Let's Encrypt
Вік
3 mo New
Зафіксований статус
Контент недоступний 404
PhishDestroy
DestroyList
У списку
Обсяг даних12 recorded checks
VirusTotal 11 / 92 URLQuery 1 threat-system alert PhishStats checked — no match recorded OTX no community references CF Radar scan completed URLScan capture збережений звіт URLScan verdict Аналіз завершено Блокування DNS не перевірено TLS valid certificate, 52d WHOIS 3 mo old Знімок екрана 3 captures · 3 sources Ланцюжок перенаправлень не досліджено
Розвіддані з мережевої безпеки
Threat Detection Systems 1 alert
Detection System Indicator Verdict Alert
DNS4EU vishnudas18.github.io malicious Sinkholed

Процес реагування на загрози Pipeline

Відкриття
Checks
Reports
Доступність
11/12

Статус у публічних блоклистах

Збережений знімок

Аналітика доменів

Домен
URLScan Verdict Аналіз завершено score 0 report ↗
Сервер / ASN GitHub.com · AS54113 Fastly, Inc.
IP Context Fastly shared edge origin IP hidden Репутація Edge-IP не пов’язана з цим доменом.
Провайдер платформи GitHub
Контакт для скаргabuse@github.com
IP-адреса 185.199.108.153 CDN
ГеолокаціяUS San Francisco, US
МережаAS54113 · GitHub, Inc
Зворотний пошук IPviewdns.info → rapiddns.io →
Початкова IP-адреса прихована за проксі CDN. Результати зворотного IP для крайової адреси містять непов’язаних орендарів; для пошуку джерела потрібен пасивний DNS або дані прозорості сертифіката.
Статус HTTP404 Not Found
Час до першої недоступності 55 days
Що ми враховуємо Час, що минув від першого збереженого звіту про порушення до першого спостереження, що вміст був недоступний. Це не встановлює причину.
Що містить кожен звіт Збережені записи вихідних звітів можуть посилатися на докази, доступні на той час, наприклад вердикти постачальників, реєстраційні дані, деталі хостингу, класифікації або знімки екрана. Ця сторінка не визначає точного доставленого корисного навантаження, квитанції, підтвердження чи дії одержувача.
Технічні деталіDNS, SAN-адреси SSL, мітки часу
Вперше виявлено14.05.2026
IoC Extractionscanned 01.08.20260 wallet · 0 Telegram IoCs
Submitted URLhttp://vishnudas18.github.io/Apple-Ui
TLS Fingerprint
TLS Observationvalid from 06.04.2026scanned 14.05.2026
TLS SAN Domainsgithub.comgithub.iogithubusercontent.com
Заголовок сторінки
Site not found · GitHub Pages
Сертифікат TLS
Valid transport encryption · Виданий Let's Encrypt · valid for 52 days
Технології · 3 identified
Varnish
Caching

Varnish is a reverse caching proxy.

www.varnish-cache.org 100% впевненості
GitHub Pages
PaaS

GitHub Pages is a static site hosting service.

pages.github.com 100% впевненості
Fastly
CDN

Fastly is a cloud computing services provider. Fastly's cloud platform provides a content delivery network, Internet security services, load balancing, and video & streaming services.

www.fastly.com 100% впевненості
Detected via Cloudflare Radar · Wappalyzer engine
Поскаржитися на цей домен Надішліть докази та допоможіть захистити інших

Аналіз VirusTotal

11 / 92 постачальників безпеки позначили цей домен
View on VT
Last analyzed
ADMINUSLabs
Criminal IP
alphaMountain.ai
BitDefender
Emsisoft
Fortinet
G-Data
Lionic
Netcraft
Sophos
Webroot
Докази та зовнішні звітиIndependent lookups and source reports
Victim safety and official reportingImmediate actions and verified reporting channels
If credentials were compromised, report immediately. Do not engage with recovery scammers.

Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.

Європол
Знайдіть офіційний канал звітності для вашої країни ЄС
National police directory
Остерігайтеся шахраїв, які обіцяють повернути втрачені кошти! Злочинці можуть знову зв’язатися з жертвами, видаючи себе за слідчих, адвокатів або агентів із відновлення. Не сплачуйте авансових зборів і не діліться обліковими даними. Дізнайтеся більше про шахрайство у сфері відшкодування збитків →

Зверніться до місцевих органів влади

Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.

Довідник 97 країн
Чернетка за допомогою штучного інтелекту — деталі інциденту обробляються постачальником штучного інтелекту Перегляньте та подайте його самостійно
Вбудувати цей звітRead-only HTML widget
HTML · IFRAME

Вбудувати цей звіт

Поділіться цією інформацією про загрози на своєму веб-сайті або в блозі

embed.html
<iframe
  src="https://phishdestroy.io/uk/embed/domain/vishnudas18.github.io"
  title="PhishDestroy threat report for vishnudas18.github.io"
  width="100%" height="320"
  loading="lazy"
  referrerpolicy="no-referrer"
  sandbox="allow-same-origin allow-popups allow-popups-to-escape-sandbox"
  style="border:0;border-radius:12px;max-width:100%"
></iframe>