emprenderenzo336-cell[.]github[.]io
“Site not found · GitHub Pages”
证据摘要
PhishDestroy identifies emprenderenzo336-cell.github.io as an active crypto drainer posing a high-risk threat through fraudulent cryptocurrency transaction interception. The domain leverages a GitHub Pages hosting service, often abused for quick deployment of malicious web assets, to mimic legitimate cryptocurrency wallet services or exchanges. Unlike typical phishing pages focused on credential theft, this crypto drainer is engineered to silently siphon digital assets by exploiting wallet connectivity, particularly targeting users of popular DeFi platforms or centralized exchanges. Given its zero detection rate on VirusTotal (10/95 engines as of latest scan) and the deployment on reputable infrastructure (Let's Encrypt SSL, GitHub Inc.), this domain represents a stealthy and evolving threat that evades conventional defenses. This domain was flagged using multiple technical indicators and contextual analysis. The domain resolves to IP address 185.199.108.153 via GitHub Pages’ content delivery network, a known hosting environment frequently exploited due to its low barrier to entry and high trust scores from security vendors. The domain employs a Let's Encrypt-issued SSL certificate, enhancing its authenticity by displaying a valid padlock icon in browsers. Notably, the domain has not been identified on any public blocklists at the time of analysis, and its recent creation (linked to seed 6a9fcd) suggests opportunistic deployment. Its low detection rate on VirusTotal indicates that signature-based defenses have not yet adapted to this variant, increasing the likelihood of successful compromise. Risk mitigation requires immediate and targeted action. Users should avoid interacting with any wallet connections or transaction prompts originating from this domain or its associated pages. Organizations are advised to deploy behavioral detection rules focusing on outbound cryptocurrency traffic from endpoints and monitor for unusual wallet connection requests. GitHub should be notified to suspend the malicious repository hosting the page. Administrators should also implement DNS-level blocking for the domain and corresponding IP (185.199.108.153) and distribute threat intelligence alerts to crypto-savvy employees. Given the absence of conventional signatures, heuristic and behavioral analysis remains critical in detecting similar threats. Regular audits of wallet extensions and transaction histories are strongly recommended to detect unauthorized transfers promptly.
Data Coverage
网络安全情报
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| DNS4EU | emprenderenzo336-cell.github.io |
malicious | Sinkholed |
威胁响应 Pipeline
阻止列表覆盖
监控中的外部数据源 10 个 · 已存快照 2026年8月11日
技术
识别出 3 项高置信度技术
VirusTotal 分析
网站性能分析
Google PageSpeed Insights — mobile performance audit of emprenderenzo336-cell.github.io · checked May 13, 2026
您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。
检查任意域名
使用存储的阻止列表、WHOIS、DNS 和公共扫描证据进行威胁分析
立即扫描举报网络钓鱼
将可疑域名提交至我们的威胁数据库——保护社区
报告实时威胁动态
最近的网络钓鱼报告和观察到的可用性变化
监控