cnvmp3-fb[.]pages[.]dev
“cnvmp3 - Free facebook Video Downloader (1080p, Up to 4K)”
ملخص الأدلة
Analysis of the domain cnvmp3-fb.pages.dev indicates it is an active phishing infrastructure targeting Facebook credentials, as of July 29, 2026. The domain is hosted under Cloudflare Pages (pages.dev), a platform frequently exploited for rapid phishing deployment due to its free tier and automatic SSL. It resolves to the Cloudflare Anycast IP 188.114.97.3, a common address for legitimate and malicious sites alike, making IP-based blocking less effective without additional context. Nameservers hugh.ns.cloudflare.com and leanna.ns.cloudflare.com confirm Cloudflare, Inc. as the registrar and DNS provider, consistent with the hosting origin.
Two of 91 security vendors on VirusTotal have flagged this domain, a modest detection rate that suggests either early-stage abuse or evasion of broader scrutiny. The domain appears on one security blocklist, specifically PhishDestroy, which specializes in credential phishing detection. No additional blocklist presence, Safe Browsing alerts, or Open Threat Exchange (OTX) pulses were identified in the available data, limiting visibility into historical abuse patterns. The exact content and phishing kit in use remain unconfirmed, as no page title, brand target, or scam type beyond 'generic phishing' was provided.
However, the inclusion of 'fb' in the subdomain strongly suggests a Facebook-themed lure, a common tactic for harvesting social media credentials. Defenders should treat this domain as high-risk for credential theft, particularly in environments where Facebook access is relevant. Recommended actions include blocking the domain at DNS and web proxy layers, monitoring for connections to 188.114.97.3 in logs, and alerting users to avoid interaction. Further analysis of the page content and kit fingerprinting would clarify the specific phishing mechanics, but the current evidence supports immediate containment.
Data Coverage
استخبارات أمن الشبكات
مسار الاستجابة للتهديدات Pipeline
تغطية قوائم الحظر
١٠ مصادر خارجية مراقبة · لقطة محفوظة 11/08/2026
المخطط الزمني للاكتشاف
-
حالة النطاق
يمكن الوصول إليه ← يتعذر الوصول إليه
تحليل VirusTotal
هل تأثرت بهذا الموقع؟
إذا أدخلت بيانات اعتماد الحساب أو المعلومات الشخصية أو معلومات الدفع أو قمت بتنزيل ملف من هذا النطاق، فاتخذ إجراءً فوريًا. فيما يلي موارد لمساعدتك في الإبلاغ عن الحادث وحماية نفسك.
أبلغ السلطات المحلية
حدد بلدك للحصول على الاتصالات الرسمية المتعلقة بالجرائم الإلكترونية أو إنشاء مسودة شكوى →.
تحقق من أي نطاق
تحليل التهديدات باستخدام قائمة الحظر المخزنة، وWHOIS، وDNS، وأدلة الفحص العامة
امسح الآنالإبلاغ عن محاولة تصيد احتيالي
أرسل النطاقات المشبوهة إلى قاعدة بيانات التهديدات الخاصة بنا — ساهم في حماية المجتمع
إبلاغتحديثات فورية حول التهديدات
تقارير التصيد الاحتيالي الأخيرة وتغييرات التوفر الملحوظة
مراقبةابقَ على اطلاع، وابقَ آمنًا
راقب التهديدات في الوقت الفعلي أو اعترض على هذا الإدراج إذا كنت تعتقد أنه إنذار كاذب