paololuck[.]github[.]io
“Site not found · GitHub Pages”
Resumo das evidências
Domain paololuck.github.io has been identified as hosting a generic credential-harvesting phishing page targeting unsuspecting users. The site masquerades as a legitimate service to trick visitors into surrendering login credentials, files, or cryptocurrency via embedded JavaScript drainer logic. Campaigns leveraging GitHub Pages are increasingly common due to the reputable domain and free hosting, allowing threat actors to blend malicious payloads with legitimate static content. No specific brand is mimicked in open-source reporting; instead, the page appears designed to capture any input provided by the victim, indicating a flexible, commodity-style phishing kit available to cybercriminals. The drainer kit is lightweight, client-side, and relies on form submissions to external endpoints controlled by the actor.
PhishDestroy’s telemetry confirms the following technical indicators tied to paololuck.github.io: a VirusTotal detection ratio of 6 out of 95 security vendors as of the latest scan, resolving to IP address 185.199.108.153 via GitHub Pages infrastructure. The domain is served over HTTPS with a Let’s Encrypt certificate, and it is registered through GitHub, Inc., aligning with the platform’s standard Page domain pattern (username.github.io). The domain has been confirmed present on one public blocklist and is currently flagged by OISD, indicating recognized malicious infrastructure. While the exact creation date is not provided in open sources, the presence of a valid SSL certificate suggests recent setup aimed at evading takedown via reputational filters.
At this time, paololuck.github.io remains actively serving malicious content with an elevated risk rating. GitHub’s abuse team has been notified via the platform’s established reporting channels to initiate page deactivation. Until takedown occurs, the domain continues to pose a direct threat to end users who may inadvertently access it. Organizations and users are strongly advised to block both the domain and the associated IP address using existing DNS filtering policies. SIEM rules should query for outbound connections to 185.199.108.153 and signatures tied to known drainer payloads. Remaining exposure can be reduced by user education on verifying URLs, especially those hosted on consumer-friendly platforms like GitHub Pages, and enforcing multi-factor authentication across all high-value accounts. Monitoring for submissions to external domains mimicking paololuck.github.io should continue as threat actors often recycle similar kits under alternate usernames.
Data Coverage
Inteligência de segurança de rede
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| DNS4EU | paololuck.github.io |
malicious | Sinkholed |
Pipeline de resposta a ameaças
Cobertura de listas de bloqueio
10 fontes externas monitoradas · instantâneo de 11/08/2026
10 fontes externas monitoradas Sem correspondência
Tecnologias
3 tecnologias identificadas com alta confiança
Análise do VirusTotal
Análise de desempenho do site
Google PageSpeed Insights — mobile performance audit of paololuck.github.io · checked May 11, 2026
Você foi afetado por este site?
Se você inseriu credenciais de conta, informações pessoais ou de pagamento, ou baixou um arquivo deste domínio, tome medidas imediatas. Abaixo estão os recursos para ajudá-lo a relatar o incidente e se proteger.
Notifique as autoridades locais
Selecione seu país para obter contactos oficiais do cibercrime ou crie um rascunho de reclamação →.
Verificar qualquer domínio
Análise de ameaças usando lista de bloqueio armazenada, WHOIS, DNS e evidências de verificação pública
Digitalize agoraDenunciar phishing
Envie domínios suspeitos para nosso banco de dados de ameaças — proteja a comunidade
DenunciarFeed de ameaças em tempo real
Relatórios recentes de phishing e alterações de disponibilidade observadas
MonitorarMantenha-se informado, mantenha-se seguro
Monitore ameaças em tempo real ou conteste esta listagem caso acredite que se trate de um falso positivo