Analysis indicates that the subdomain shivani2k5.github.io is currently active and has been classified as a generic phishing site. The domain is hosted on GitHub Pages, as evidenced by the registration through GitHub, Inc. and the resolution to the IP address 185.199.108.153, which belongs to GitHub's content delivery network. Google Safe Browsing flags the URL for social engineering, confirming that the site is being used to lure users into providing credentials or personal information. The domain appears on a single security blocklist and has been added to the PhishDestroy blocklist, demonstrating that at least one anti‑phishing service has identified malicious activity associated with it.
No DNS NS records were returned in the available data, which limits the ability to assess the full name‑server infrastructure. VirusTotal has not provided any vendor detections for this domain, but the absence of detections does not imply safety. No additional indicators such as SSL certificate details, HTTP response codes, page titles, or content hashes are presently available, leaving the exact nature of the phishing payload unknown. Consequently, defenders cannot rely on content‑based signatures and must focus on network‑level controls.
Given the current evidence, security teams should block the domain at the DNS or proxy level, monitor outbound connections to the associated IP range, and update intrusion‑detection signatures to flag any HTTP requests to shivani2k5.github.io. Incident response procedures should include user awareness alerts that reference the domain and its classification as a social‑engineering phishing host. Continuous monitoring of GitHub‑hosted subdomains is recommended, as the platform can be abused to serve malicious pages with minimal infrastructure overhead. Further analysis of the site’s HTML and network traffic is required to determine the specific credential‑harvesting techniques employed.