MALICIOUS — CRITICAL
bercode21[.]github[.]io
PhishDestroy identifies the domain bercode21.github.io as an active PayPal phishing campaign, currently hosting fraudulent login pages designed to harvest user credentials.
- VirusTotal
- 13/94
- Blocklists
- No stored match
- Доступність
- Контент недоступний · HTTP 404
Do not enter credentials, seed phrases, payment details, or personal information on this domain.
Jump to section
bercode21.github.io — Контент недоступний (HTTP 404). Уособлення бренду: PayPal; Тип шахрайства: Brand Impersonation. Зведення доказів: VirusTotal 13/94 (ADMINUSLabs, alphaMountain.ai, BitDefender, Chong Lua Dao, CyRadar); URLQuery 1 alert; URLScan malicious verdict; CF Radar malicious; PhishDestroy score 94/100. Реєстратор: GitHub.
Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.
Evidence Analysis
PhishDestroy identifies the domain bercode21.github.io as an active PayPal phishing campaign, currently hosting fraudulent login pages designed to harvest user credentials. This domain is actively engaged in credential theft and remains operational despite multiple detection mechanisms. The threat involves the impersonation of PayPal's official services to deceive victims into entering sensitive financial information.
This domain was flagged by PhishingDB and is currently detected by 13 of 95 VirusTotal security vendors, indicating a high-risk threat with a significant failure rate in detection. The domain resolves to IP address 185.199.111.153, registered through GitHub, Inc., and has appeared on 1 security blocklist. Additionally, the SSL certificate issued by Let's Encrypt further legitimizes the facade, increasing the likelihood of successful deception. The domain exhibits low trust scores across security platforms, reinforcing its malicious intent.
As of the latest intelligence, bercode21.github.io remains active and poses a severe risk to unsuspecting users. Immediate action is required to prevent credential theft and financial fraud. Users should avoid interacting with this domain entirely and report any encounters to their respective cybersecurity teams or relevant authorities. Organizations are advised to update firewall rules, DNS blocklists, and endpoint protection systems to block all traffic to and from this domain. Proactive monitoring of network traffic for connections to this IP address or domain is strongly recommended to mitigate potential breaches.
Обсяг даних12 recorded checks
Розвіддані з мережевої безпеки
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| Cloudflare DNS | bercode21.github.io |
malicious | Sinkholed |
Процес реагування на загрози Pipeline
Статус у публічних блоклистах
Технології · 3 identified
Static site hosting provided free by GitHub.
Edge cloud platform — CDN, security and edge compute.
Аналіз VirusTotal
Аналіз продуктивності сайту
Google PageSpeed Insights — mobile performance audit of bercode21.github.io · checked Apr 14, 2026
Докази та зовнішні звітиIndependent lookups and source reports
Victim safety and official reportingImmediate actions and verified reporting channels
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.