Analysis on 01 August 2026 confirms that the domain shubhamkumar-25.github.io remains active and is associated with a high‑risk phishing threat. VirusTotal records indicate that eight of ninety‑one scanning engines have flagged the domain as malicious, demonstrating a non‑trivial consensus among security products. Independent blocklists have also responded: PhishDestroy and OpenPhish have listed the domain, and it appears on two additional public blocklists, reinforcing its reputation as hostile infrastructure. Registration metadata shows the domain was created through GitHub, Inc., a legitimate provider that is frequently abused for malicious hosting.
DNS resolution points to the IP address 185.199.108.153, which belongs to the GitHub Pages network; no alternate nameservers were identified, suggesting the default GitHub configuration is in use. The lack of publicly available page title or SSL details limits current visibility into the exact payload or lure employed, and no further attribution such as ASN, country, or kit information is available. Consequently, defenders should proactively block the domain at network perimeter and endpoint filters, incorporate its IP address into threat‑intelligence feeds, and monitor for any outbound connections to the GitHub Pages range that may indicate compromised accounts.
Continuous re‑scanning on VirusTotal and periodic checks against blocklist updates are recommended to capture any changes in detection status. Organizations that employ email gateways or web proxies should ensure their URL filtering rules include this domain to mitigate user exposure. Given the existing evidence, the domain should be treated as a confirmed malicious actor until a formal takedown is observed.