As of July 31, 2026, hafsa-noor1.github.io is an active domain identified as a high-risk generic phishing site. Infrastructure analysis reveals the domain is registered through GitHub, Inc. and currently resolves to IP address 185.199.108.153. The domain’s nameserver configuration is missing or misconfigured, as indicated by NS_NOT_FOUND, which is atypical for legitimate operations and often observed in domains used for malicious purposes. This site has been blocked by PhishDestroy and appears on at least one security blocklist, confirming that it is recognized by threat intelligence providers as a phishing risk.
Google Safe Browsing has flagged hafsa-noor1.github.io for social engineering, a strong indicator that the domain is actively engaged in deceptive practices targeting users. VirusTotal scans from 91 vendors currently show no detections, but this absence does not constitute evidence of safety; threat actors frequently evade detection for extended periods, and blocklisting by reputable sources is sufficient to justify caution.
The exact content and targeting of the site have not been analysed, as no information regarding the page title, brand, or specific scam type is available. Defenders should treat this domain as hostile and block all access immediately. Continued monitoring is recommended, as phishing sites hosted on platforms like GitHub Pages often change tactics or infrastructure to evade detection. Any interaction with hafsa-noor1.github.io poses a substantial risk to users and networks, and incident response teams should ensure it remains prohibited within their environments.