MALICIOUS — CRITICAL
bercode21[.]github[.]io
PhishDestroy identifies the domain bercode21.github.io as an active PayPal phishing campaign, currently hosting fraudulent login pages designed to harvest user credentials.
- VirusTotal
- 13/94
- Blocklists
- No stored match
- Ketersediaan
- Konten tidak tersedia · HTTP 404
Do not enter credentials, seed phrases, payment details, or personal information on this domain.
Jump to section
bercode21.github.io — Konten tidak tersedia (HTTP 404). Peniruan identitas merek: PayPal; Jenis penipuan: Brand Impersonation. Ringkasan bukti: VirusTotal 13/94 (ADMINUSLabs, alphaMountain.ai, BitDefender, Chong Lua Dao, CyRadar); URLQuery 1 alert; URLScan malicious verdict; CF Radar malicious; PhishDestroy score 94/100. Registrar: GitHub.
Analisis terperinci PhishDestroy AI di bawah tetap berbahasa Inggris untuk menjaga catatan forensik asli.
Evidence Analysis
PhishDestroy identifies the domain bercode21.github.io as an active PayPal phishing campaign, currently hosting fraudulent login pages designed to harvest user credentials. This domain is actively engaged in credential theft and remains operational despite multiple detection mechanisms. The threat involves the impersonation of PayPal's official services to deceive victims into entering sensitive financial information.
This domain was flagged by PhishingDB and is currently detected by 13 of 95 VirusTotal security vendors, indicating a high-risk threat with a significant failure rate in detection. The domain resolves to IP address 185.199.111.153, registered through GitHub, Inc., and has appeared on 1 security blocklist. Additionally, the SSL certificate issued by Let's Encrypt further legitimizes the facade, increasing the likelihood of successful deception. The domain exhibits low trust scores across security platforms, reinforcing its malicious intent.
As of the latest intelligence, bercode21.github.io remains active and poses a severe risk to unsuspecting users. Immediate action is required to prevent credential theft and financial fraud. Users should avoid interacting with this domain entirely and report any encounters to their respective cybersecurity teams or relevant authorities. Organizations are advised to update firewall rules, DNS blocklists, and endpoint protection systems to block all traffic to and from this domain. Proactive monitoring of network traffic for connections to this IP address or domain is strongly recommended to mitigate potential breaches.
Cakupan data12 recorded checks
Intelijen Keamanan Jaringan
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| Cloudflare DNS | bercode21.github.io |
malicious | Sinkholed |
Alur Tanggapan Ancaman Pipeline
Status Daftar Blokir Publik
Teknologi · 3 identified
Static site hosting provided free by GitHub.
Edge cloud platform — CDN, security and edge compute.
Analisis VirusTotal
Analisis Performa Situs
Google PageSpeed Insights — mobile performance audit of bercode21.github.io · checked Apr 14, 2026
Bukti & Laporan EksternalIndependent lookups and source reports
Victim safety and official reportingImmediate actions and verified reporting channels
Jika Anda memasukkan kredensial akun, informasi pribadi atau pembayaran, atau mengunduh file dari domain ini, segera ambil tindakan. Di bawah ini adalah sumber daya untuk membantu Anda melaporkan insiden tersebut dan melindungi diri Anda sendiri.
Laporkan kepada Pihak Berwenang di Daerah Anda
Pilih negara Anda untuk mendapatkan kontak resmi kejahatan dunia maya, atau membuat draf pengaduan →.