cerdeirahugo139-alt[.]github[.]io
“Orange Eysines MP — Gestion des Stocks”
证据摘要
This domain, cerdeirahugo139-alt.github.io, is confirmed to host a credential harvesting phishing site targeting users of Orange Eysines MP under the guise of "Gestion des Stocks" (Stock Management). The site is designed to deceive visitors into submitting sensitive login credentials, likely for corporate or personal accounts associated with the legitimate Orange Eysines service. Analysis indicates the phishing page employs social engineering tactics, presenting a fabricated login interface that closely resembles the authentic Orange Eysines portal, thereby increasing the likelihood of successful credential theft. Infrastructure analysis reveals multiple high-confidence indicators of malicious activity. The domain is flagged by 5 out of 95 security vendors on VirusTotal, a notable detection rate for a recently deployed phishing site. It is hosted on GitHub Pages infrastructure, resolving to the IP address 185.199.111.153, which is part of AS54113 (Fastly, Inc.) located in the United States. The domain appears on one security blocklist, and its SSL certificate is issued by Let's Encrypt (R12), a common choice for threat actors due to its free and automated issuance process. The page title, "Orange Eysines MP — Gestion des Stocks," directly references the targeted entity, further corroborating the phishing intent. Users who have visited cerdeirahugo139-alt.github.io or interacted with its content should take immediate remedial actions. First, any credentials entered on the site must be considered compromised and should be changed immediately across all platforms where they were reused. System administrators should monitor for unauthorized access attempts or anomalous login activity, particularly for accounts associated with Orange Eysines or related services. Additionally, users should verify the legitimacy of any unexpected communications or login prompts by directly accessing the official Orange Eysines portal through verified channels. Organizations are advised to block the domain and its resolving IP at the network perimeter to prevent further exposure.
Data Coverage
威胁响应 Pipeline
阻止列表覆盖
监控中的外部数据源 10 个 · 已存快照 2026年8月13日
VirusTotal 分析
您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。
检查任意域名
使用存储的阻止列表、WHOIS、DNS 和公共扫描证据进行威胁分析
立即扫描举报网络钓鱼
将可疑域名提交至我们的威胁数据库——保护社区
报告实时威胁动态
最近的网络钓鱼报告和观察到的可用性变化
监控