luckmall[.]vip
Verifica phishing e sicurezza per luckmall.vip
“502 Bad Gateway”
luckmall.vip — Contenuto non disponibile (HTTP 502). Tipo di truffa: Credential Phishing. Riepilogo delle prove: VirusTotal 15/91 (ADMINUSLabs, alphaMountain.ai, BitDefender, Chong Lua Dao, CRDF); PhishDestroy score 95/100.
L’analisi dettagliata di PhishDestroy AI resta in inglese per preservare il rapporto forense originale.
Evidence Analysis
On 2026-08-02 the domain luckmall.vip was identified as an active generic phishing infrastructure. The domain is currently blocked by the PhishDestroy sink‑hole network, indicating that it has been observed delivering credential‑stealing payloads. VirusTotal reports that 15 of 91 scanning engines flag the domain as malicious, providing independent confirmation of its hostile nature. The domain also appears on a public security blocklist, further corroborating its reputation as a threat vector.
Technical resolution shows that luckmall.vip resolves to the IPv4 address 163.181.254.138. No additional data on the autonomous system, hosting provider, or geographic location has been disclosed in public records. Passive DNS and WHOIS lookups have not revealed registration details, and SSL/TLS certificates for the host are not publicly visible, suggesting either the use of self‑signed certificates or that the site is accessed over plain HTTP. HTTP status codes, page title, and content analysis have not been published, leaving the exact phishing lures employed by the site unknown.
Given the available evidence, defenders should assume that luckmall.vip is being used to harvest credentials or other sensitive information. The domain should be added to local and network‑level block lists, and outbound connections to 163.181.254.138 should be monitored or denied. Continuous re‑evaluation is advised, as future scans may reveal additional malicious indicators such as malicious JavaScript, payload delivery, or new hosting changes. Organizations employing phishing‑prevention gateways should update their threat feeds with the indicators of compromise listed herein.
Copertura dei dati12 recorded checks
Informazioni sulla sicurezza di rete
Pipeline di risposta alle minacce
Stato della lista di blocco pubblica
Analisi di VirusTotal
Dati e relazioni esterneIndependent lookups and source reports
Victim safety and official reportingImmediate actions and verified reporting channels
Se hai inserito credenziali dell'account, informazioni personali o di pagamento oppure hai scaricato un file da questo dominio, agisci immediatamente. Di seguito sono riportate le risorse per aiutarti a segnalare l'incidente e proteggerti.
Segnalalo alle autorità locali
Seleziona il tuo Paese per ottenere contatti ufficiali del crimine informatico o creare una bozza di reclamo →.