Analysis of atharvnavlakhe.github.io indicates that the domain is actively being used in a generic phishing campaign as of the report date, July 31, 2026. The domain is hosted on GitHub Pages, resolving to the IP address 185.199.108.153, and was registered through GitHub, Inc. Infrastructure checks show that the domain appears on a single security blocklist and is currently blocked by the PhishDestroy service. VirusTotal records reveal that the domain was scanned by 91 AV vendors, none of which raised a detection at the time of scanning; this absence of detections should not be interpreted as evidence of safety.
No nameserver information is available in the intelligence set, and the domain’s SSL/TLS configuration, HTTP response codes, and page title have not been disclosed, leaving those aspects of the surface unknown. The limited visibility into the site’s content and lack of additional threat intelligence sources mean that the full scope of the phishing operation cannot be precisely determined. Defenders should treat the domain as malicious, enforce blocking at perimeter filters, and add the domain to internal blocklists.
Continuous monitoring of the IP address 185.199.108.153 for any changes in hosting or additional malicious activity is advised, as is periodic re‑scanning with multi‑vendor engines to capture any future detections. Organizations with users who may encounter GitHub‑hosted phishing pages should educate them about verifying URLs and encourage the use of web reputation services that include the PhishDestroy feed.