Analysis indicates that the domain facebooklogin239.blogspot.com is currently active and has been identified as a credential phishing site targeting Facebook users. The domain is hosted on Google’s Blogger platform, as evidenced by the registrar information "registered through Google LLC." It resolves to the IP address 142.251.14.132, which belongs to Google’s infrastructure. The domain has been listed on three independent phishing blocklists and is actively blocked by the PhishDestroy, OpenPhish, and Phishunt feeds. VirusTotal records show that six of ninety‑one scanned security vendors have flagged the domain as malicious, reinforcing the suspicion of phishing activity.
The nameserver query returned "NS_NOT_FOUND," suggesting that standard DNS delegation information is unavailable or obscured. No public SSL certificate details, HTTP status codes, or page title information have been disclosed, limiting the ability to assess the site’s transport security or content cues. Likewise, no Open Threat Exchange (OTX) or additional threat‑intel identifiers have been provided. The absence of these data points introduces uncertainty regarding the exact phishing kit in use, the presence of HTTPS, and any additional payload characteristics.
Given the confirmed blocklist listings, the registrar association with Google, and the multi‑vendor detections, defenders should treat any traffic to this domain as malicious. Recommended actions include updating firewall and proxy rules to block the domain and its resolved IP address, adding the domain to internal URL filtering lists, and monitoring for any authentication attempts that reference "facebooklogin239.blogspot.com." Incident response teams should also consider reviewing logs for prior connections to the IP 142.251.14.132 and correlating with user reports of unexpected Facebook login prompts. Continuous monitoring of threat‑intel feeds for further attribution or changes in detection status is advised.