shahzebjan45[.]github[.]io
“Site not found · GitHub Pages”
PhishDestroy identifies shahzebjan45.github.io as a live, elevated-risk phishing asset currently leveraging GitHub Pages to host fake login prompts. The domain masquerades as a legitimate service to harvest user credentials, making it a direct threat to authentication integrity. Based on telemetry, this site triggers 17 out of 95 security vendors, confirming its malicious classification. It resolves to AS208475 via IP 185.199.108.153 and operates under a Let’s Encrypt SSL certificate. Registered through GitHub, Inc., the page exploits trust in the GitHub domain while hosting deceptive content. Despite its innocuous appearance, the combination of flagged detections and live status underscores its elevated risk to end users seeking to authenticate online.
Technical indicators reveal a lightweight footprint: the domain lacks historical depth, pointing to a recently deployed lure. The SSL certificate, issued by Let’s Encrypt, enhances the page’s credibility by disguising malicious intent under a green padlock. Network analysis routes traffic through Fastly’s infrastructure (AS208475) – a legitimate CDN commonly abused to host short-lived phishing pages. With 17 vendors flagging it and no presence on major blocklists at time of detection, shahzebjan45.github.io represents a stealthy, evasive threat. The absence of long-term registration details suggests a disposable asset, rapidly deployed for credential harvesting campaigns across multiple verticals.
Mitigation requires immediate network and user-level actions. Block the domain and its resolving IP (185.199.108.153) at perimeter defenses using DNS sinkholing and firewall rules. Flag any outbound traffic to this domain for investigation due to its confirmed malicious intent. Since it hosts a fake login portal, enforce multi-factor authentication (MFA) to reduce the impact of potential credential theft. Warn users to verify URLs via hover-over checks and avoid entering credentials on untrusted sites, especially those hosted on free domains like GitHub Pages. For SOC teams, ingest this IOC into SIEM dashboards and update threat intelligence feeds to preempt similar lures. Act now to prevent credential compromise and data exfiltration.
网络安全情报
威胁响应 Pipeline
阻止列表覆盖
10 个来源 · 于 2026年8月10日 同步
VirusTotal 分析
网站性能分析
Google PageSpeed Insights — mobile performance audit of shahzebjan45.github.io · checked Mar 26, 2026
您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。
检查任意域名
使用存储的阻止列表、WHOIS、DNS 和公共扫描证据进行威胁分析
立即扫描举报网络钓鱼
将可疑域名提交至我们的威胁数据库——保护社区
报告实时威胁动态
最近的网络钓鱼报告和观察到的可用性变化
监控