nubexx776[.]github[.]io
nubexx776.github.io 网络钓鱼与安全检查
“Site not found · GitHub Pages”
nubexx776.github.io — 内容不可用 (HTTP 404). 品牌冒充:Google; 诈骗类型:Brand Impersonation. 证据摘要: VirusTotal 18/94 (ADMINUSLabs, alphaMountain.ai, BitDefender, Certego, Chong Lua Dao); URLQuery 4 alerts; URLScan malicious verdict; Google Safe Browsing flagged; PhishDestroy score 100/100. 注册商: GitHub.
为保留原始取证记录,下方的 PhishDestroy AI 详细分析仍使用英文。
The domain nubexx776.github.io is assessed as a high-risk threat, specifically categorized as brand impersonation. This domain is actively impersonating Google, a well-known and widely trusted brand, which significantly increases the likelihood of users falling victim to the scam.
Infrastructure analysis reveals that the domain nubexx776.github.io was created on April 22, 2026, and is registered through GitHub, Inc. The domain resolves to the IP address 185.199.108.153, which is located in the United States and is associated with GitHub, Inc. According to VirusTotal, 18 out of 95 security vendors have flagged this domain as malicious, indicating a notable level of suspicion among the cybersecurity community. The domain also appears on one security blocklist and has been flagged by Google Safe Browsing as a phishing site. The SSL certificate is issued by Let's Encrypt, which, while legitimate, does not imply the site's safety. The page title 'Site not found · GitHub Pages' suggests that the site may have been taken down or is not currently hosted, but the domain remains active and can still pose a threat.
To mitigate the risks associated with brand impersonation, users should be cautious when clicking links or visiting URLs that seem suspicious, especially those purporting to be from trusted brands like Google. Organizations should educate their employees about the dangers of such impersonation attacks and implement strict verification protocols for any communication claiming to be from known entities. Network administrators should consider adding this domain to their firewall and DNS blocklists to prevent access. Additionally, users should verify the URL and look for signs of phishing, such as misspellings, unusual domain extensions, or requests for sensitive information.
网络安全情报
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| YARAhub by abuse.ch | nubexx776.github.io/fishing/script.js |
malware | Detects file containing Telegram Bot API |
| YARAhub by abuse.ch | nubexx776.github.io/fishing/ |
malware | Detects file containing Telegram Bot API |
| OpenDNS | nubexx776.github.io |
phishing | Phishing Block |
| DNS4EU | nubexx776.github.io |
malicious | Sinkholed |
威胁响应 Pipeline
公共封禁名单状态
所用技术 · 3 identified
Fastly is a cloud computing services provider. Fastly's cloud platform provides a content delivery network, Internet security services, load balancing, and video & streaming services.
www.fastly.com 置信度 100%VirusTotal 分析
网站性能分析
Google PageSpeed Insights — mobile performance audit of nubexx776.github.io · checked Apr 22, 2026
证据与外部报告
您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。