Is neon59903-alt.github.io safe?

http://neon59903-alt.github.io/

28/100
High Risk

Analysis coverage: partial · 2 of 5 core capabilities

Verdict

GitHub Pages subdomain flagged as social engineering despite returning 404

neon59903-alt.github.io serves only the standard GitHub Pages 404 error page. Google Safe Browsing blocks it as SOCIAL_ENGINEERING and VirusTotal reports 11 malicious detections focused on phishing, though the detections are stale and no active content or credential collection is present.

Read the full analysis
12 antivirus engines flagged this URLalphaMountain.ai, Emsisoft, ESET, Forcepoint ThreatSeeker, Fortinet
Do not visit or trust links to neon59903-alt.github.io. If you arrived via email or message, treat the source as suspicious and report it.
Saved captureView evidence

01 · Investigation Brief

Investigation Brief

neon59903-alt.github.io serves only the standard GitHub Pages 404 error page. Google Safe Browsing blocks it as SOCIAL_ENGINEERING and VirusTotal reports 11 malicious detections focused on phishing, though the detections are stale and no active content or credential collection is present.

What the site appears to do

The URL hosts no GitHub Pages site and immediately returns the official 404 error stating there is no Pages site here. No downloads, forms, redirects, or external resources load.

Strongest evidence and limitations

Google Safe Browsing flags the URL for social engineering. VirusTotal shows 11 engines labeling it malicious or phishing, primarily from alphaMountain, Emsisoft, ESET, Fortinet, and others. The hosting IP belongs to GitHub's CDN with only moderate abuse reports.

Limitations include stale VirusTotal data, complete absence of page content or credential fields, and no observed harmful actions on access.

Practical user impact

Browsers enforcing Safe Browsing will block the page. The subdomain itself carries operator-level risk from prior association with flagged activity, but the current 404 means no immediate malware or phishing payload is delivered.

Why the score is 28

A browser-protection feed identifies this URL as malware or social engineering. Coverage remains separate so missing sources cannot be mistaken for clean results.

02 · Security Evidence

Security evidence

Antivirus Engines

Saved result - stale

12 engines flagged this URL

Every saved adverse engine is listed below. The full provider matrix remains available for audit.

Malicious
11
Suspicious
1
Total
92
Adverse antivirus results
EngineFinding
alphaMountain.aiMaliciousphishing
EmsisoftMaliciousphishing
ESETMaliciousphishing
Forcepoint ThreatSeekerMaliciousphishing
FortinetMaliciousphishing
GridinsoftMaliciousphishing
LionicMaliciousphishing
NetcraftMaliciousmalicious
RisingMaliciousphishing
SophosMaliciousphishing
WebrootMaliciousmalicious
URLQuerySuspicioussuspicious
All 92 engine results
  • alphaMountain.ai - phishing - Malicious
  • Emsisoft - phishing - Malicious
  • ESET - phishing - Malicious
  • Forcepoint ThreatSeeker - phishing - Malicious
  • Fortinet - phishing - Malicious
  • Gridinsoft - phishing - Malicious
  • Lionic - phishing - Malicious
  • Netcraft - malicious - Malicious
  • Rising - phishing - Malicious
  • Sophos - phishing - Malicious
  • Webroot - malicious - Malicious
  • URLQuery - suspicious - Suspicious
  • 0xSI_f33d - unrated - Clean
  • Abusix - clean - Clean
  • Acronis - clean - Clean
  • ADMINUSLabs - clean - Clean
  • AILabs (MONITORAPP) - clean - Clean
  • AlienVault - clean - Clean
  • AlphaSOC - unrated - Clean
  • Antiy-AVL - clean - Clean
  • ArcSight Threat Intelligence - unrated - Clean
  • AutoShun - unrated - Clean
  • Bfore.Ai PreCrime - unrated - Clean
  • BitDefender - clean - Clean
  • Bkav - unrated - Clean
  • BlockList - clean - Clean
  • Blueliv - clean - Clean
  • Certego - clean - Clean
  • ChainPatrol - clean - Clean
  • Chong Lua Dao - clean - Clean
  • CINS Army - clean - Clean
  • Cluster25 - unrated - Clean
  • CRDF - clean - Clean
  • Criminal IP - unrated - Clean
  • CSIS Security Group - unrated - Clean
  • CTX AI - clean - Clean
  • Cyan - unrated - Clean
  • Cyble - clean - Clean
  • CyRadar - clean - Clean
  • desenmascara.me - clean - Clean
  • DNS8 - unrated - Clean
  • Dr.Web - clean - Clean
  • EmergingThreats - clean - Clean
  • Ermes - unrated - Clean
  • ESTsecurity - clean - Clean
  • Fortra - unrated - Clean
  • G-Data - clean - Clean
  • GCP Abuse Intelligence - unrated - Clean
  • Google Safe Browsing - clean - Clean
  • GreenSnow - clean - Clean
  • GreyNoise - unrated - Clean
  • Guardpot - unrated - Clean
  • Heimdal Security - clean - Clean
  • Hunt.io Intelligence - unrated - Clean
  • IPsum - clean - Clean
  • Juniper Networks - clean - Clean
  • K7AntiVirus - unrated - Clean
  • Kaspersky - clean - Clean
  • LevelBlue - unrated - Clean
  • Lumu - unrated - Clean
  • Malwared - clean - Clean
  • MalwarePatrol - clean - Clean
  • MalwareURL - unrated - Clean
  • Mimecast - unrated - Clean
  • OpenPhish - clean - Clean
  • PhishFort - unrated - Clean
  • Phishing Database - clean - Clean
  • Phishtank - clean - Clean
  • PREBYTES - clean - Clean
  • PrecisionSec - unrated - Clean
  • Quick Heal - clean - Clean
  • Quttera - clean - Clean
  • SafeToOpen - unrated - Clean
  • Sangfor - clean - Clean
  • Sansec eComscan - unrated - Clean
  • Scantitan - clean - Clean
  • SCUMWARE.org - clean - Clean
  • Seclookup - clean - Clean
  • Snort IP sample list - unrated - Clean
  • SOCRadar - unrated - Clean
  • StopForumSpam - clean - Clean
  • Sucuri SiteCheck - clean - Clean
  • ThreatHive - clean - Clean
  • URLhaus - clean - Clean
  • Viettel Threat Intelligence - clean - Clean
  • VIPRE - unrated - Clean
  • ViriBack - clean - Clean
  • VX Vault - clean - Clean
  • Xcitium Verdict Cloud - clean - Clean
  • Yandex Safebrowsing - clean - Clean
  • ZeroCERT - clean - Clean
  • ZeroFox - unrated - Clean

Security Scans

Browser Threat Feed
This URL appears on threat lists

Detected threat categories: SOCIAL_ENGINEERING.

What we observed

CAPTURED PAGE
neon59903-alt.github.io
What our review noticed on this page

Captured during this scan in a safe sandbox. Opening this report does not revisit the site. Marker positions are approximate. See full visual analysis →

Visual analysis

Visual context from the captured page

Standard GitHub 404 page with no site content

Context only

What the captured page showed

1 observation
  1. 01

    Standard GitHub 404 page with no site content

03 · Investigation Story

Investigation story

The behavior, reputation, and operator evidence that explains how this site may affect a visitor.
  1. 1

    What the site claims

    The page presents itself as a service operating on neon59903-alt.github.io.

  2. 2

    What we observed

    The page itself could not be fully inspected, so the report relies on the other saved checks.

  3. 3

    What independent research found

    No complete independent-research result was available in this saved report.

  4. 4

    What remains unverified

    3 of the five core capabilities did not complete, so those gaps remain visible in the coverage ledger.

What kind of site and risk is this?

Threat category

Phishing & Impersonation

Service and business model

Unknown

Unknown

Observed behavior

No disruptive browser behavior saved

Evidence behind this classification

  1. 01Google Safe Browsing: SOCIAL_ENGINEERING threat
  2. 02A browser-protection feed identifies this URL as malware or social engineering.
  3. 03Saved antivirus evidence is adverse but is not fresh enough for a current conviction.

If this is a scam — what it means for you

You were probably about to log in or type personal details here.

If it is, anything you enter — username, password, card number, one-time code — goes straight to criminals, who use it to take over your real accounts and drain them.

If this is a scam, how it works

The typical trap, step by step

This site is unverified — it may be legitimate. If it is a scam, this is the playbook pages like it follow:

  1. They clone a real login page (a bank, email provider, PayPal, a courier) pixel-for-pixel.

  2. You're driven here by an email, text, or ad with an urgent reason to “verify”, “unlock”, or “confirm” your account.

  3. You type your username and password — which flow straight to the scammers instead of the real company.

  4. They log into your real account, change the password, and drain it or sell the access.

If a site follows these steps, treat it as unsafe — close it and don't enter anything.

Reputation Sources

How this domain rates across independent threat-intelligence and blocklist providers.

Google Safe Browsing
ListedCheck ↗
VirusTotal
ListedCheck ↗
AbuseIPDB
Not listedCheck ↗

04 · Domain & Infrastructure

Domain & infrastructure

Timeline · identity · encryption · redirects · hosting

The plumbing behind the site — who registered it, how it’s encrypted, where it’s hosted, and where it links out. A valid certificate or a calm server doesn’t mean the business is honest — scam sites pass these checks too. Use this to corroborate the verdict, not to overturn it.

Infrastructure map

How the saved page connected to the wider web.

Domainneon59903-alt.github.io
Redirects toneon59903-alt.github.io
Hosted byGitHub, Inc.

Domain & Encryption

Domain History
AgeUnknown
RegistrarHidden
RegisteredUnknown
ExpiresUnknown
Owner privacyUnknown
Encryption Certificate
StatusInvalid
Protocolnone
IssuerNone
ExpiresInvalid Date (0d)
Self-signedNo
Hosting & Technology
HostingGitHub, Inc.
Server locationUS

Server Reputation

Abuse Intelligence
Confidence score24%
Reports on file15
ISPGitHub, Inc.
Usage typeContent Delivery Network

05 · Evidence Ledger

Evidence ledger

Coverage, provenance, and source freshness remain separate so a missing check is never mistaken for a clean result.
Completed analysis

The conclusion is supported by the evidence saved with this report.

AntiviruspartialBrowser threat feedcompletePage contentpartialAnalysiscompleteVisual evidenceunavailable

Technical threat

Malware, phishing, credential theft and hostile infrastructure.

malicious

Additional evidence review · Additional evidence review

Operator / customer risk

Complaints, withdrawals, business conduct and commercial traps.

unknown

No confirmed evidence in this dimension.

Source coverage and freshness

Status shows whether usable evidence was saved; finding shows what that evidence observed.

Antivirus
Result: 12 of 92 engines flagged
Limited
Adverse
Freshness: stale fallback · Aug 1, 2026
Browser protection
Result: 1 browser threat category matched
Completed
Adverse
Page content
Result: Page content was not available for semantic review
Limited
No saved finding
Visual evidence
Result: 1 visible observation saved with the page capture
Completed
No adverse finding
Independent research
Result: Independent research was not available for this report
Unavailable
No saved finding

06 · Your Next Move

Your next move

Proceed with caution

Our automated review flagged enough risk that you should treat this site as unverified.

  • Analyst recommendation

    Do not visit or trust links to neon59903-alt.github.io. If you arrived via email or message, treat the source as suspicious and report it.

  • Treat neon59903-alt.github.io as unverified

    Do not enter credentials or send money until you have independently verified the business.

  • Verify the business through independent channels

    Check the company's social profiles, registry records, and search for recent news or reviews that are not hosted on the site itself.

  • Never use irreversible payment methods

    Crypto, gift cards, wire transfers, and cash apps offer zero buyer protection. Use a credit card or PayPal if you must pay.

  • Share your experience

    If you have additional context, drop a comment below or post on the MalwareTips forum.

    Open
Final verdictLevel 4 of 5
28/100 safety

High Risk

GitHub Pages subdomain flagged as social engineering despite returning 404

neon59903-alt.github.io serves only the standard GitHub Pages 404 error page. Google Safe Browsing blocks it as SOCIAL_ENGINEERING and VirusTotal reports 11 malicious detections focused on phishing, though the detections are stale and no active content or credential collection is present.

  1. 01

    Google Safe Browsing: SOCIAL_ENGINEERING threat

  2. 02

    11 VirusTotal engines flag phishing or malicious

  3. 03

    Direct 404 from GitHub Pages with no content served

Do not visit or trust links to neon59903-alt.github.io. If you arrived via email or message, treat the source as suspicious and report it.
Saved page capture
Evidence balance6 signals
Positive
1
Limited
3
Risk
2
Analysis coverage
74%
partial coverage
Core capabilities
2/5
completed checks
Source coverage
2/5
sources complete
Evidence checks
2/8
completed checks flagged
Technical threatDANGEROUS95/100 risk
Operator / customer riskNot confirmed50/100 risk
Safety range

Saved evidence only. Missing checks are never treated as a clean result.

Scan another URL

07 · Community

Community

0 community contributions

Share what happened, what the site requested, and what others should watch for.

Community reviews never change the scanner verdict.

Loading…
Loading comments…

08 · Safety FAQ

Safety FAQ

Common questions, answered directly from the scan data above — so the answers reflect the saved verdict and evidence in this report.

Is neon59903-alt.github.io a scam or a legit website?
neon59903-alt.github.io raises serious red flags as a phishing & impersonation — do not enter your login or personal details. Our review tagged it for phishing-impersonation. 12 of 92 security engines flag it (11 as outright malicious). The domain is an unknown age. It may not be an outright scam, but the risk is high enough that you should verify it independently before trusting it with money or data.
Is neon59903-alt.github.io safe to use?
neon59903-alt.github.io has a Safety Score of 28/100 (High Risk). Analysis coverage is partial at 74%. Avoid login, payment and downloads.
I already paid or entered my details on neon59903-alt.github.io — what should I do?
If you've already paid or handed over details on neon59903-alt.github.io, act quickly. 1) Contact your bank or card issuer immediately and ask to dispute the charge or open a chargeback — the sooner you act, the better your odds. 2) Report the site to the U.S. FTC at reportfraud.ftc.gov or the FBI's IC3 at ic3.gov, and in the UK to Action Fraud at actionfraud.police.uk. 3) If you entered a password, change it on neon59903-alt.github.io and anywhere you reused it, and turn on two-factor authentication. 4) Watch your bank and email for follow-up fraud, and keep screenshots as evidence.
Can I get my money back from neon59903-alt.github.io?
Often yes, if you act fast. Payments made by credit or debit card can frequently be reversed through a chargeback or dispute — contact your bank right away and explain it was a fraudulent site. Bank transfers and gift-card or voucher payments are much harder to recover, but you should still report them to your bank and to the FTC (reportfraud.ftc.gov) or Action Fraud (actionfraud.police.uk). Avoid any "refund" or "recovery" service that contacts you first — it's usually a follow-up scam.
Did neon59903-alt.github.io steal my password or personal information?
If you entered anything on neon59903-alt.github.io, assume it was captured. Phishing pages exist purely to harvest what you type — usernames, passwords, card numbers, or one-time codes. Change the password immediately on the real site and anywhere you reused it, enable two-factor authentication, and if you entered card or banking details, contact your bank about the risk of fraud. Also be alert for follow-up "security" calls or emails that try to exploit the same information.
How do I report neon59903-alt.github.io?
You can report neon59903-alt.github.io through several official channels: the U.S. FTC at reportfraud.ftc.gov, the FBI's Internet Crime Complaint Center (IC3) at ic3.gov, and — in the UK — Action Fraud at actionfraud.police.uk. You can also flag it to Google Safe Browsing (safebrowsing.google.com/safebrowsing/report_phish) so other browsers warn about it, and report it to the company being impersonated if there is one. Reporting helps get scam sites taken down faster.
neon59903-alt.github.io looks professional — how can it still be a scam?
Modern scams are built to look convincing. A valid SSL padlock, a polished template, stock photos, fake reviews, and a trust badge can all be added in minutes and prove nothing about who runs the site. Scammers buy cheap domains, clone real designs, and copy legal pages wholesale. That's exactly why an automated review that checks the domain's age, hosting, blacklists, and behaviour — rather than just how the page looks — is more reliable than a first impression.
Has neon59903-alt.github.io been flagged by antivirus engines?
Yes. 12 of 92 antivirus and blocklist engines in our malware network flagged neon59903-alt.github.io, 11 of them as outright malicious. Even a single detection from a reputable engine is a meaningful warning, and multiple detections rarely happen by accident.
Is neon59903-alt.github.io on any phishing or malware blacklists?
Yes. neon59903-alt.github.io is listed on the major browser blocklist feeds under: SOCIAL_ENGINEERING. Modern browsers use these feeds to warn or block billions of users before a page even loads — a listing here is one of the strongest safety signals there is.
How old is the neon59903-alt.github.io domain?
neon59903-alt.github.io is an unknown age. A multi-year registration history is one of the stronger signals against a scam, though it's never a guarantee on its own — established domains can still be misused.
Does neon59903-alt.github.io have a valid SSL certificate?
No — neon59903-alt.github.io has an invalid or broken SSL certificate, so browsers will show a security warning. Combined with the other signals, we recommend avoiding it.
How often is the neon59903-alt.github.io report updated?
This report is a record of the scan run on August 1, 2026, and the verdict reflects that point in time. Scam sites change fast — they can go live, get flagged, or vanish within days — so if you believe something about neon59903-alt.github.io has changed, MalwareTips staff can run a fresh scan that re-checks every signal from scratch and republishes an updated verdict.