MALICIOUS — CRITICAL
paololuck[.]github[.]io
6 of 92 security engines flagged the domain; URLQuery recorded 1 threat-system alert; the latest stored check returned HTTP 404.
- VirusTotal
- 6/92
- Blocklists
- No stored match
- sẵn có
- Nội dung không có sẵn · HTTP 404
Do not enter credentials, seed phrases, payment details, or personal information on this domain.
Jump to section
paololuck.github.io — Nội dung không có sẵn (HTTP 404). Loại lừa đảo: Generic Phishing. Tóm tắt bằng chứng: VirusTotal 6/92 (ADMINUSLabs, alphaMountain.ai, G-Data, Gridinsoft, MalwareURL); URLQuery 1 alert; PhishDestroy score 73/100. Nhà đăng ký: GitHub.
Phân tích chi tiết của PhishDestroy AI bên dưới được giữ bằng tiếng Anh để bảo toàn hồ sơ pháp chứng gốc.
Evidence Digest
paololuck.github.io has a stored critical classification with an evidence score of 73/100. 6 of 92 security engines flagged the domain. The reported host is a tenant on Fastly at 185.199.108.153 (Fastly, Inc., US). The latest stored check on 9 Aug 2026 returned HTTP 404 and includes a capture.
Stored generated summary (templated)mistral · 11/05/2026
Retained for the record. This text repeats stored detection facts and is not presented as authored analysis.
Domain paololuck.github.io has been identified as hosting a generic credential-harvesting phishing page targeting unsuspecting users. The site masquerades as a legitimate service to trick visitors into surrendering login credentials, files, or cryptocurrency via embedded JavaScript drainer logic. Campaigns leveraging GitHub Pages are increasingly common due to the reputable domain and free hosting, allowing threat actors to blend malicious payloads with legitimate static content. No specific brand is mimicked in open-source reporting; instead, the page appears designed to capture any input provided by the victim, indicating a flexible, commodity-style phishing kit available to cybercriminals. The drainer kit is lightweight, client-side, and relies on form submissions to external endpoints controlled by the actor.
PhishDestroy’s telemetry confirms the following technical indicators tied to paololuck.github.io: a VirusTotal detection ratio of 6 out of 95 security vendors as of the latest scan, resolving to IP address 185.199.108.153 via GitHub Pages infrastructure. The domain is served over HTTPS with a Let’s Encrypt certificate, and it is registered through GitHub, Inc., aligning with the platform’s standard Page domain pattern (username.github.io). The domain has been confirmed present on one public blocklist and is currently flagged by OISD, indicating recognized malicious infrastructure. While the exact creation date is not provided in open sources, the presence of a valid SSL certificate suggests recent setup aimed at evading takedown via reputational filters.
At this time, paololuck.github.io remains actively serving malicious content with an elevated risk rating. GitHub’s abuse team has been notified via the platform’s established reporting channels to initiate page deactivation. Until takedown occurs, the domain continues to pose a direct threat to end users who may inadvertently access it. Organizations and users are strongly advised to block both the domain and the associated IP address using existing DNS filtering policies. SIEM rules should query for outbound connections to 185.199.108.153 and signatures tied to known drainer payloads. Remaining exposure can be reduced by user education on verifying URLs, especially those hosted on consumer-friendly platforms like GitHub Pages, and enforcing multi-factor authentication across all high-value accounts. Monitoring for submissions to external domains mimicking paololuck.github.io should continue as threat actors often recycle similar kits under alternate usernames.
Phạm vi dữ liệu12 recorded checks
Tình báo an ninh mạng
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| DNS4EU | paololuck.github.io |
malicious | Sinkholed |
Pipeline ứng phó với các mối đe dọa
Trạng thái trong danh sách chặn công khai
Công nghệ · 3 identified
Fastly is a cloud computing services provider. Fastly's cloud platform provides a content delivery network, Internet security services, load balancing, and video & streaming services.
www.fastly.com Độ tin cậy 100%Phân tích của VirusTotal
Phân tích hiệu suất trang
Google PageSpeed Insights — mobile performance audit of paololuck.github.io · checked May 11, 2026
Bằng chứng và các báo cáo bên ngoàiIndependent lookups and source reports
Victim safety and official reportingImmediate actions and verified reporting channels
Nếu bạn đã nhập thông tin xác thực tài khoản, thông tin cá nhân hoặc thông tin thanh toán hoặc đã tải xuống tệp từ miền này, hãy hành động ngay lập tức. Dưới đây là các nguồn lực giúp bạn báo cáo vụ việc và bảo vệ chính mình.
Hãy báo cáo với chính quyền địa phương
Chọn quốc gia của bạn để nhận liên hệ tội phạm mạng chính thức hoặc soạn thảo đơn khiếu nại →.