joel-johnson-exe[.]github[.]io
“Site not found · GitHub Pages”
Resumo das evidências
PhishDestroy identifies joel-johnson-exe.github.io as an active credential theft domain leveraging GitHub Pages for legitimacy. This domain, hosted on IP 185.199.108.153 with a Let's Encrypt SSL certificate, is currently propagating through phishing campaigns aimed at harvesting user credentials under the guise of a personal or professional page. The domain's infrastructure—registered via GitHub, Inc.—provides a veneer of trustworthiness, which threat actors exploit to bypass traditional security filters. Initial exposure to this domain could result in unauthorized access to sensitive accounts or data exfiltration, particularly if users are tricked into entering login credentials.
Threat analysis reveals a coordinated effort to impersonate a reputable individual or entity, likely targeting professionals or users familiar with the impersonated person. VirusTotal confirms this threat with 8 out of 95 security vendors flagging the domain as malicious, indicating widespread, though not universal, detection. The domain resolves to a GitHub-owned IP range (185.199.108.153), which is commonly abused by threat actors to host malicious content due to GitHub's trusted reputation. While GitHub Pages is a legitimate service, the misuse of this platform for credential theft campaigns underscores the need for heightened vigilance. The domain's SSL certificate, issued by Let's Encrypt, further lends an air of legitimacy, making it harder for users to discern the malicious nature of the site.
If you or your users have visited joel-johnson-exe.github.io, assume credentials entered on the site have been compromised. Immediately rotate passwords for all accounts associated with this domain, including email, social media, and any other services where the same credentials might have been reused. Enable multi-factor authentication (MFA) wherever possible to add an additional layer of security. Report the domain to your security team or via platforms like VirusTotal to aid in broader threat intelligence sharing. For organizational environments, consider blocking the domain and IP (185.199.108.153) at the network perimeter to prevent further exposure. Remain cautious of unsolicited emails or messages referencing this domain, as they may be part of a larger social engineering campaign.
Data Coverage
Inteligência de segurança de rede
Pipeline de resposta a ameaças
Cobertura de listas de bloqueio
10 fontes externas monitoradas · instantâneo de 11/08/2026
10 fontes externas monitoradas Sem correspondência
Análise do VirusTotal
Análise de desempenho do site
Google PageSpeed Insights — mobile performance audit of joel-johnson-exe.github.io · checked Mar 28, 2026
Você foi afetado por este site?
Se você inseriu credenciais de conta, informações pessoais ou de pagamento, ou baixou um arquivo deste domínio, tome medidas imediatas. Abaixo estão os recursos para ajudá-lo a relatar o incidente e se proteger.
Notifique as autoridades locais
Selecione seu país para obter contactos oficiais do cibercrime ou crie um rascunho de reclamação →.
Verificar qualquer domínio
Análise de ameaças usando lista de bloqueio armazenada, WHOIS, DNS e evidências de verificação pública
Digitalize agoraDenunciar phishing
Envie domínios suspeitos para nosso banco de dados de ameaças — proteja a comunidade
DenunciarFeed de ameaças em tempo real
Relatórios recentes de phishing e alterações de disponibilidade observadas
MonitorarMantenha-se informado, mantenha-se seguro
Monitore ameaças em tempo real ou conteste esta listagem caso acredite que se trate de um falso positivo