paololuck[.]github[.]io
“Site not found · GitHub Pages”
Domain paololuck.github.io has been identified as hosting a generic credential-harvesting phishing page targeting unsuspecting users. The site masquerades as a legitimate service to trick visitors into surrendering login credentials, files, or cryptocurrency via embedded JavaScript drainer logic. Campaigns leveraging GitHub Pages are increasingly common due to the reputable domain and free hosting, allowing threat actors to blend malicious payloads with legitimate static content. No specific brand is mimicked in open-source reporting; instead, the page appears designed to capture any input provided by the victim, indicating a flexible, commodity-style phishing kit available to cybercriminals. The drainer kit is lightweight, client-side, and relies on form submissions to external endpoints controlled by the actor.
PhishDestroy’s telemetry confirms the following technical indicators tied to paololuck.github.io: a VirusTotal detection ratio of 6 out of 95 security vendors as of the latest scan, resolving to IP address 185.199.108.153 via GitHub Pages infrastructure. The domain is served over HTTPS with a Let’s Encrypt certificate, and it is registered through GitHub, Inc., aligning with the platform’s standard Page domain pattern (username.github.io). The domain has been confirmed present on one public blocklist and is currently flagged by OISD, indicating recognized malicious infrastructure. While the exact creation date is not provided in open sources, the presence of a valid SSL certificate suggests recent setup aimed at evading takedown via reputational filters.
At this time, paololuck.github.io remains actively serving malicious content with an elevated risk rating. GitHub’s abuse team has been notified via the platform’s established reporting channels to initiate page deactivation. Until takedown occurs, the domain continues to pose a direct threat to end users who may inadvertently access it. Organizations and users are strongly advised to block both the domain and the associated IP address using existing DNS filtering policies. SIEM rules should query for outbound connections to 185.199.108.153 and signatures tied to known drainer payloads. Remaining exposure can be reduced by user education on verifying URLs, especially those hosted on consumer-friendly platforms like GitHub Pages, and enforcing multi-factor authentication across all high-value accounts. Monitoring for submissions to external domains mimicking paololuck.github.io should continue as threat actors often recycle similar kits under alternate usernames.
Intelijen Keamanan Jaringan
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| DNS4EU | paololuck.github.io |
malicious | Sinkholed |
Alur Tanggapan Ancaman Pipeline
Cakupan daftar blokir
10 sumber · disinkronkan 09/08/2026
Teknologi
3 teknologi dengan keyakinan tinggi teridentifikasi
Analisis VirusTotal
Analisis Performa Situs
Google PageSpeed Insights — mobile performance audit of paololuck.github.io · checked May 11, 2026
Apakah Anda Terpengaruh oleh Situs Ini?
Jika Anda memasukkan kredensial akun, informasi pribadi atau pembayaran, atau mengunduh file dari domain ini, segera ambil tindakan. Di bawah ini adalah sumber daya untuk membantu Anda melaporkan insiden tersebut dan melindungi diri Anda sendiri.
Laporkan kepada Pihak Berwenang di Daerah Anda
Pilih negara Anda untuk mendapatkan kontak resmi kejahatan dunia maya, atau membuat draf pengaduan →.
Periksa Domain Apa Pun
Analisis ancaman menggunakan daftar blokir yang disimpan, WHOIS, DNS, dan bukti pemindaian publik
Pindai SekarangLaporkan Phishing
Laporkan domain yang mencurigakan ke basis data ancaman kami — lindungi komunitas
LaporanPemberitahuan Ancaman Real-Time
Laporan phishing terbaru dan perubahan ketersediaan yang diamati
PantauTetap Terinformasi, Tetap Aman
Pantau ancaman secara langsung atau ajukan keberatan terhadap daftar ini jika Anda yakin ini merupakan false positive