Analysis shows that rashi-garg904.github.io is hosted on GitHub Pages, resolving to the IP address 185.199.108.153, which belongs to the GitHub, Inc. infrastructure. The domain registration is recorded as being performed through GitHub, Inc., and authoritative nameserver queries return no results, indicating that the service relies on GitHub's default DNS handling. VirusTotal has processed the domain with 91 scanning engines; none of the engines flagged the site as malicious, but the lack of detections does not constitute evidence of safety.
The domain is listed on one external security blocklist and is actively blocked by the PhishDestroy service, confirming that at least one security provider has identified phishing‑related activity linked to this host. The threat classification in the intelligence feed is generic phishing, and the domain remains active as of the report date. Defenders should assume the domain may be used to host phishing content or to facilitate credential‑harvesting campaigns, especially given its presence on a blocklist despite the clean VirusTotal result.
Recommended mitigation actions include adding the fully qualified domain name to outbound deny lists in firewalls, proxy appliances, and DNS filtering solutions, and ensuring that any HTTP or HTTPS requests to 185.199.108.153 are blocked or logged for further inspection. Security teams should monitor email gateways for messages containing links to this domain, capture any such messages for sandbox analysis, and correlate network logs to identify potential user interactions with the site. Continuous re‑evaluation is advised, as additional detections may appear on broader threat feeds, and the domain's status could evolve as threat actors adapt their tactics.