The domain security-server-docs--govmentdded.replit.app is presently active and classified as a high‑risk generic phishing site. According to VirusTotal, 12 of 91 scanned security vendors have flagged the domain, indicating a moderate level of consensus among detection engines. DNS interrogation returned no authoritative nameserver records (NS_NOT_FOUND), which suggests the domain relies on Replit’s default dynamic resolution rather than custom name server configuration.
The domain resolves to IP address 34.117.33.233, an address owned by Replit Inc., the same entity listed as the registrar. Google Safe Browsing has marked the URL for social engineering, reinforcing the phishing assessment. The site is listed on a single external security blocklist and is actively blocked by the PhishDestroy filtering service.
No public page title, SSL certificate details, or HTTP response codes have been disclosed, leaving the exact content and delivery mechanisms unverified. Given the confirmed detections, safe‑browsing flag, and blocklist presence, defenders should proactively block the domain at network perimeters, incorporate it into local threat intelligence feeds, and monitor the associated IP for any anomalous traffic. Continuous observation of Replit‑hosted infrastructure for similar patterns is advised, as the platform can be leveraged for rapid deployment of malicious actors.