mahidhar-3997[.]github[.]io
“Site not found · GitHub Pages”
证据摘要
PhishDestroy identifies mahidhar-3997.github.io (185.199.108.153) as a live credential theft scam impersonating a legitimate brand via GitHub-hosted infrastructure to harvest user login details. This domain leverages GitHub Pages to appear authentic while hosting a fraudulent login interface designed to siphon credentials unbeknownst to visitors. Threat actors use this false authenticity to bypass traditional email filtering and social-engineering filters, tricking users into entering sensitive credentials that are subsequently exfiltrated to attacker-controlled repositories. The operational TTP involves rapid domain rotation within GitHub's free hosting environment, making takedowns slower due to GitHub's abuse-handling delays. This campaign specifically targets users familiar with crypto or financial services by mimicking login portals of well-known exchanges, thereby increasing the likelihood of credential submission.
This domain was flagged by 12 out of 95 VirusTotal security vendors, indicating moderate detection by the security community yet remaining active and accessible. Registered through GitHub, Inc., it resolves to IP 185.199.108.153 and operates under a Let’s Encrypt SSL certificate, enhancing its perceived legitimacy. The active status and low blocklist uptake suggest ongoing deployment, with attackers likely iterating on branding and lure content to evade detection. DNS resolution history and passive DNS analysis show consistent hosting since domain creation, with no signs of redirection or cloaking that would indicate intermittent shutdown by hosting providers. The combination of GitHub’s free hosting, modern TLS encryption, and low VT coverage creates an elevated-risk phishing vector that circumvents both technical and user-level defenses.
Users who visited mahidhar-3997.github.io should immediately revoke any entered credentials via the legitimate brand’s account recovery portal and enable multi-factor authentication if not already configured. Clear browser cache and cookies related to the domain, then scan devices with updated antivirus software to detect potential credential-stealing malware or browser extensions. Report the domain to your organization’s security team and to Google Safe Browsing or PhishTank to aid in collective defense. Avoid re-engaging with the site and warn colleagues or community members who may have been targeted. Monitor financial and account activity for unauthorized access for at least 90 days due to the high risk of credential reuse across platforms.
Data Coverage
网络安全情报
威胁响应 Pipeline
阻止列表覆盖
监控中的外部数据源 10 个 · 已存快照 2026年8月12日
VirusTotal 分析
网站性能分析
Google PageSpeed Insights — mobile performance audit of mahidhar-3997.github.io · checked Mar 29, 2026
您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。
检查任意域名
使用存储的阻止列表、WHOIS、DNS 和公共扫描证据进行威胁分析
立即扫描举报网络钓鱼
将可疑域名提交至我们的威胁数据库——保护社区
报告实时威胁动态
最近的网络钓鱼报告和观察到的可用性变化
监控