On 31 July 2026 analysts observed that the domain haleema7502.github.io remains active and is hosted on GitHub Pages. Registration information indicates the domain was created through GitHub, Inc., and no authoritative name server records were returned (NS_NOT_FOUND), which is consistent with GitHub’s default DNS configuration for user‑generated sites. DNS resolution points to IP address 185.199.110.153, an address owned by GitHub’s content‑delivery network and commonly used for legitimate static website hosting. The same IP is shared by many unrelated sites, which reduces the uniqueness of the hosting fingerprint but does not preclude abuse.
The domain appears on a single external security blocklist and is explicitly blocked by the PhishDestroy service. Google Safe Browsing classifies the URL as a social‑engineering threat, indicating that it has been reported or detected as attempting to deceive users. A VirusTotal scan conducted by 91 antivirus engines did not produce any current detections; however, the lack of detections is not evidence of safety and may reflect the limited visibility of a freshly deployed phishing page. No SSL/TLS certificate details, HTTP response codes, page titles, or additional content evidence were available in the current intelligence set, leaving the exact phishing payload and the targeted brand undefined.
Consequently, the precise lure and victim profile cannot be confirmed at this time. Given the active status, hosting on a legitimate CDN, and the presence on reputable blocklists, defenders should treat the domain as high‑risk. Recommended actions include adding the fully qualified domain to network and endpoint deny lists, monitoring for DNS changes that could indicate a shift to a more persistent hosting provider, and employing URL‑filtering solutions that respect Google Safe Browsing verdicts. Continuous re‑scanning with dynamic analysis tools is advised to capture any future payload changes.