facebook-psm[.]blogspot[.]ru
“Facebook”
ملخص الأدلة
The domain facebook-psm.blogspot.ru is currently active and has been classified as a high‑risk brand‑impersonation site targeting Facebook. Intelligence sources list the domain on two reputable security blocklists, PhishDestroy and PhishingDB, confirming that it is being used to deceive users. The page title returned by the server is simply “Facebook”, which aligns with the declared impersonation of the Facebook brand.
Infrastructure analysis shows the domain is registered through Google, using ASN 15169, and resolves to IP address 142.250.185.97, which belongs to Google LLC in the United States. The host presents a valid SSL certificate issued by Google Trust Services under the WE2 profile, indicating that TLS termination is performed by the same provider that hosts the site. Detected technologies include Blogger, Java, Python, OpenGSE, and HTTP/3, suggesting a standard blog platform enhanced with server‑side scripting.
VirusTotal has flagged the domain on 13 of 95 scanned security vendors, providing additional evidence of malicious intent. The HTTP response is a 302 redirect, a common technique for steering victims to credential‑collection pages after an initial landing. Although the page title is known, the actual content has not been captured, leaving the specifics of the phishing flow uncertain. The domain’s presence on multiple blocklists and the multi‑vendor detection rate support a high confidence rating for phishing activity.
Defenders should immediately block traffic to facebook-psm.blogspot.ru at network perimeter and email gateways, and consider adding the IP 142.250.185.97 to deny lists where appropriate. Continuous monitoring of DNS queries for this domain is advised, as the infrastructure could be repurposed for additional malicious campaigns. Threat‑intel teams should share indicators of compromise with peer organizations to accelerate detection and containment.
Data Coverage
استخبارات أمن الشبكات
مسار الاستجابة للتهديدات Pipeline
تغطية قوائم الحظر
١٠ مصادر خارجية مراقبة · لقطة محفوظة 13/08/2026
المخطط الزمني للاكتشاف
-
حالة النطاق
يمكن الوصول إليه ← يتعذر الوصول إليه
-
Cloudflare Radar
تم حفظ فحص Cloudflare Radar · فتح الفحص
تحليل VirusTotal
هل تأثرت بهذا الموقع؟
إذا أدخلت بيانات اعتماد الحساب أو المعلومات الشخصية أو معلومات الدفع أو قمت بتنزيل ملف من هذا النطاق، فاتخذ إجراءً فوريًا. فيما يلي موارد لمساعدتك في الإبلاغ عن الحادث وحماية نفسك.
أبلغ السلطات المحلية
حدد بلدك للحصول على الاتصالات الرسمية المتعلقة بالجرائم الإلكترونية أو إنشاء مسودة شكوى →.
تحقق من أي نطاق
تحليل التهديدات باستخدام قائمة الحظر المخزنة، وWHOIS، وDNS، وأدلة الفحص العامة
امسح الآنالإبلاغ عن محاولة تصيد احتيالي
أرسل النطاقات المشبوهة إلى قاعدة بيانات التهديدات الخاصة بنا — ساهم في حماية المجتمع
إبلاغتحديثات فورية حول التهديدات
تقارير التصيد الاحتيالي الأخيرة وتغييرات التوفر الملحوظة
مراقبةابقَ على اطلاع، وابقَ آمنًا
راقب التهديدات في الوقت الفعلي أو اعترض على هذا الإدراج إذا كنت تعتقد أنه إنذار كاذب