The domain rayan-arbab.github.io is presently listed on a security blocklist and is actively flagged by Google Safe Browsing for social engineering, indicating a high‑risk phishing posture. Registration details show the domain was created through GitHub, Inc., and the authoritative name server data is unavailable (NS_NOT_FOUND), which limits visibility into DNS delegation. Network resolution points to the IP address 185.199.108.153, an address owned by GitHub’s hosting infrastructure, a common platform for compromised or abused repositories.
VirusTotal records reveal that the domain has been examined by 91 scanning engines, none of which have raised a detection at the time of analysis; the absence of alerts does not constitute validation of safety, as automated scanners may miss novel or obfuscated payloads. The domain is also present on the PhishDestroy blocklist, reinforcing the consensus that it is being used for phishing attempts. No public information is available regarding SSL certificate status, HTTP response codes, page title, or additional reputation scores, leaving those facets of the site’s behaviour unverified.
Given the confirmed presence on multiple blocklists and the Google Safe Browsing social‑engineering flag, defenders should treat any traffic to rayan-arbab.github.io as malicious. Recommended mitigations include adding the domain to deny‑list rules on perimeter firewalls, proxy filters, and endpoint protection suites, monitoring DNS logs for resolution events, and enforcing strict user awareness training to discourage credential entry on untrusted URLs. Continuous re‑evaluation is advised, as threat actors may alter hosting or content while retaining the same domain.