Zum Sicherheitsbericht springen
Checked 09.08.2026 Ref A0E4CCF1

MALICIOUS — CRITICAL

facebook-calls[.]blogspot[.]com

Analysis as of July 22, 2026 shows that the domain facebook-calls.blogspot.com is actively hosting a brand‑impersonation campaign targeting Facebook.

100/100 evidence score · Critical
VirusTotal
18/91
Blocklists
1 · Phishunt
Verfügbarkeit
Letzter bekanntermaßen aktiv · HTTP 200
Report / Add Evidence Appeal this listing
2026-07-16 10:53 UTCLetzter bekanntermaßen aktiv · HTTP 200

Do not enter credentials, seed phrases, payment details, or personal information on this domain.

⚠️
Diese Domain wurde als bösartig markiert.
Sicherheits-Engines melden eine Entdeckung: 18. Öffentliche Blocklisten, die eine Übereinstimmung melden: 1. Seien Sie äußerst vorsichtig – Geben Sie keine Anmeldeinformationen oder persönlichen Daten ein.
Jump to section
Berichtsübersicht

facebook-calls.blogspot.com — Letzter bekanntermaßen aktiv (HTTP 200). Markenidentität: Facebook; Betrugstyp: Impersonation. Zusammenfassung der Beweislage: VirusTotal 18/91 (Criminal IP, alphaMountain.ai, BitDefender, Chong Lua Dao, CyRadar); URLScan malicious verdict; Spamhaus DBL_ABUSED_PHISH; 1 external blocklist match (Phishunt); CF Radar malicious; PhishDestroy score 100/100. Registrar: Google Blogger.

Die ausführliche Analyse von PhishDestroy AI bleibt auf Englisch, damit der ursprüngliche forensische Bericht unverändert bleibt.

Evidence Analysis

Ref A0E4CCF1

Analysis as of July 22, 2026 shows that the domain facebook-calls.blogspot.com is actively hosting a brand‑impersonation campaign targeting Facebook. The site is registered through Google Blogger and resolves to the Google‑owned IP address 142.251.20.132, which is geolocated to the United States and associated with Google LLC. The TLS certificate presented by the site is issued by Google Trust Services under the WE2 hierarchy, indicating a valid HTTPS connection but offering no assurance of legitimacy. HTTP requests return a 200 status code, and the page title is simply "facebook," confirming that the domain name and title are aligned with the claimed brand target. Technical fingerprints reveal the presence of Blogger, Java, Python, OpenGSE, Google AdSense, and HTTP/3, consistent with a typical Blogger‑hosted site that may be leveraged to serve malicious content or advertisements.

VirusTotal has recorded 10 detections out of 91 scanned security vendors, demonstrating that a subset of threat intelligence engines have flagged the domain as malicious. Independent blocklists, including PhishDestroy and Phishunt, have already listed the domain, and it appears on two additional security blocklists, reinforcing its classification as high‑risk. The domain’s nameserver information is unavailable (NS_NOT_FOUND), limiting the ability to trace upstream DNS infrastructure.

While the available data confirm active impersonation of Facebook and a high risk rating, the exact payload or credential‑collection mechanisms employed by the site remain unverified, as no detailed page content analysis is provided. Defenders should therefore treat the domain as hostile: block it at perimeter firewalls, DNS resolvers, and web proxies; add it to internal URL filtering and threat‑intel feeds; and monitor for any outbound connections to the associated IP address.

VirusTotal
VirusTotal
18 det.
CF-Radar
Schädlich
URLScan
URLScan
ScamAdviser
Scamadviser
80/100
TLS-Zertifikat
Google Trust Services / WE2
Beobachteter Status
Letzter bekanntermaßen aktiv 200
PhishDestroy
DestroyList
Gelistet
Datenabdeckung13 recorded checks
VirusTotal 18 / 91 URLQuery nicht geprüft PhishStats nicht geprüft OTX no community references CF-Radar provider verdict: malicious URLScan capture gespeicherter Bericht URLScan verdict malicious DNS-Sperren nicht geprüft TLS valid certificate, 42d WHOIS not parsed Screenshot 2 captures · 2 sources Weiterleitungskette nicht untersucht Scamadviser 80/100
Erkenntnisse zur Netzwerksicherheit
CF Cloudflare Radar Verdict Schädlich
Phishing

Pipeline zur Reaktion auf Sicherheitsbedrohungen

Entdeckung
Checks
Reports
Verfügbarkeit
14/16

Status der öffentlichen Sperrliste

Gespeicherte Aufnahme

Domain-Intelligenz

Domain
URLScan Verdict Schädlich score 100 Phishing brand: Facebook report ↗
Server / ASN GSE · AS15169 Google LLC
IP-Reputation abuse score 0/100 25 reports checked 16.07.2026
Plattformanbieter Google Blogger US(US)
Abuse-Kontaktnetwork-abuse@google.com
IP-Adresse 142.251.20.132 US
StandortUS Mountain View, US
NetzwerkAS15169 · Google LLC
HTTP-Status200
Technische DetailsDNS, SSL-SANs, Zeitstempel
Erstmals entdeckt16.07.2026
DOM Analysisanalyzed 16.07.2026score 93/100
IoC Extractionscanned 29.07.20260 wallet · 0 Telegram IoCs
Submitted URLhttp://facebook-calls.blogspot.com/
TLS Fingerprint
TLS Observationvalid from 29.06.2026scanned 16.07.2026
TLS SAN Domainsblogspot.aeblogspot.alblogspot.amblogspot.bablogspot.beblogspot.bgblogspot.cablogspot.chblogspot.clblogspot.co.atblogspot.co.idblogspot.co.ilblogspot.co.keblogspot.co.nzblogspot.co.uk+55
Seitentitel
facebook
TLS-Zertifikat
Valid transport encryption · Ausgestellt von Google Trust Services / WE2 · valid for 42 days
Technologien · 6 identified
Blogger
Blogs

Blogger is a blog-publishing service that allows multi-user blogs with time-stamped entries.

www.blogger.com 100 % Konfidenz
Java
Programming languages

Java is a class-based, object-oriented programming language that is designed to have as few implementation dependencies as possible.

java.com 100 % Konfidenz
Python
Programming languages

Python is an interpreted and general-purpose programming language.

python.org 100 % Konfidenz
OpenGSE
Web servers

OpenGSE is a test suite used for testing servlet compliance. It is deployed by using WAR files that are deployed on the server engine.

code.google.com 100 % Konfidenz
Google AdSense
Advertising

Google AdSense is a program run by Google through which website publishers serve advertisements that are targeted to the site content and audience.

www.google.com 100 % Konfidenz
HTTP/3
Miscellaneous

HTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.

httpwg.org 100 % Konfidenz
Detected via Cloudflare Radar · Wappalyzer engine
Diese Domain melden Reichen Sie Beweismaterial ein und helfen Sie mit, andere zu schützen

VirusTotal-Analyse

18 / 91 Sicherheitsanbieter haben diese Domain markiert
View on VT
Last analyzed First positive detection Previous stored snapshot: 10 detections
Criminal IP
alphaMountain.ai
BitDefender
Chong Lua Dao
CyRadar
ESET
Emsisoft
Forcepoint ThreatSeeker
Fortinet
G-Data
Gridinsoft
Kaspersky
Lionic
MalwareURL
Netcraft
Sophos
VIPRE
Webroot
Analyse der Website-Konfiguration
Stored observations are retained with their original collection time.
robots.txt Present · HTTP 200
/search /share-widget
Sitemap 2 pages · HTTP 200
Nachweise und externe BerichteIndependent lookups and source reports
Victim safety and official reportingImmediate actions and verified reporting channels
If credentials were compromised, report immediately. Do not engage with recovery scammers.

Wenn Sie Kontoanmeldeinformationen, persönliche oder Zahlungsinformationen eingegeben oder eine Datei von dieser Domain heruntergeladen haben, ergreifen Sie sofort Maßnahmen. Nachfolgend finden Sie Ressourcen, die Ihnen helfen, den Vorfall zu melden und sich zu schützen.

Europol
Finden Sie den offiziellen Meldekanal für Ihr EU-Land
National police directory
Vorsicht vor Betrügern, die mit der Rückforderung von Geldern locken! Kriminelle nehmen unter Umständen erneut Kontakt zu Opfern auf und geben dabei vor, Ermittler, Anwälte oder Beitreibungsbeamte zu sein. Zahlen Sie keine Vorabgebühren und geben Sie keine Anmeldeinformationen weiter. Erfahren Sie mehr über Betrug im Zusammenhang mit Wiederaufbaumaßnahmen →

Melden Sie sich bei Ihren örtlichen Behörden

Wählen Sie Ihr Land aus, um Offizielle Kontakte im Bereich Cyberkriminalität oder einen Beschwerdeentwurf erstellen → zu erhalten.

97-Länder-Verzeichnis
KI-gestützter Entwurf – Vorfalldetails werden vom KI-Anbieter verarbeitet Überprüfen Sie es und reichen Sie es selbst ein
Diesen Bericht einbettenRead-only HTML widget
HTML · IFRAME

Diesen Bericht einbetten

Teilen Sie diese Bedrohungsinformationen auf Ihrer Website oder in Ihrem Blog

embed.html
<iframe
  src="https://phishdestroy.io/de/embed/domain/facebook-calls.blogspot.com"
  title="PhishDestroy threat report for facebook-calls.blogspot.com"
  width="100%" height="320"
  loading="lazy"
  referrerpolicy="no-referrer"
  sandbox="allow-same-origin allow-popups allow-popups-to-escape-sandbox"
  style="border:0;border-radius:12px;max-width:100%"
></iframe>