Analysis as of July 28, 2026 indicates that the GitHub‑Pages subdomain dileep-yadav-00.github.io is actively being used for credential harvesting. The domain resolves to the IP address 185.199.109.153, which is owned by GitHub, Inc., confirming that the site is hosted on standard GitHub Pages infrastructure. DNS resolution does not return custom nameserver records, implying reliance on GitHub’s default nameservers. The domain is listed on two public blocklists and is explicitly blocked by the PhishDestroy and OpenPhish feeds, demonstrating that multiple threat‑intelligence providers have observed malicious activity originating from this host.
VirusTotal reports that 13 of 91 scanning engines have flagged the domain, providing additional independent confirmation of its abusive nature. No further technical details such as SSL certificate parameters, HTTP response codes, page titles, or brand targeting have been published, leaving the exact content of the page unverified. The uncertainty around the specific phishing lures employed does not diminish the risk, given the corroborating evidence from blocklists and detection vendors.
Defenders should therefore treat dileep-yadav-00.github.io as a high‑risk indicator. Recommended mitigation steps include adding the domain to outbound denial lists, blocking DNS resolution at the recursive resolver, monitoring network traffic for connections to 185.199.109.153, and integrating the domain into SIEM correlation rules alongside the associated blocklist feeds. Continuous re‑evaluation is advised as additional forensic artefacts become available.