MALICIOUS — CRITICAL
facebook-calls[.]blogspot[.]com
Analysis as of July 22, 2026 shows that the domain facebook-calls.blogspot.com is actively hosting a brand‑impersonation campaign targeting Facebook.
- VirusTotal
- 18/91
- Blocklists
- 1 · Phishunt
- Verfügbarkeit
- Letzter bekanntermaßen aktiv · HTTP 200
Do not enter credentials, seed phrases, payment details, or personal information on this domain.
Jump to section
facebook-calls.blogspot.com — Letzter bekanntermaßen aktiv (HTTP 200). Markenidentität: Facebook; Betrugstyp: Impersonation. Zusammenfassung der Beweislage: VirusTotal 18/91 (Criminal IP, alphaMountain.ai, BitDefender, Chong Lua Dao, CyRadar); URLScan malicious verdict; Spamhaus DBL_ABUSED_PHISH; 1 external blocklist match (Phishunt); CF Radar malicious; PhishDestroy score 100/100. Registrar: Google Blogger.
Die ausführliche Analyse von PhishDestroy AI bleibt auf Englisch, damit der ursprüngliche forensische Bericht unverändert bleibt.
Evidence Analysis
Analysis as of July 22, 2026 shows that the domain facebook-calls.blogspot.com is actively hosting a brand‑impersonation campaign targeting Facebook. The site is registered through Google Blogger and resolves to the Google‑owned IP address 142.251.20.132, which is geolocated to the United States and associated with Google LLC. The TLS certificate presented by the site is issued by Google Trust Services under the WE2 hierarchy, indicating a valid HTTPS connection but offering no assurance of legitimacy. HTTP requests return a 200 status code, and the page title is simply "facebook," confirming that the domain name and title are aligned with the claimed brand target. Technical fingerprints reveal the presence of Blogger, Java, Python, OpenGSE, Google AdSense, and HTTP/3, consistent with a typical Blogger‑hosted site that may be leveraged to serve malicious content or advertisements.
VirusTotal has recorded 10 detections out of 91 scanned security vendors, demonstrating that a subset of threat intelligence engines have flagged the domain as malicious. Independent blocklists, including PhishDestroy and Phishunt, have already listed the domain, and it appears on two additional security blocklists, reinforcing its classification as high‑risk. The domain’s nameserver information is unavailable (NS_NOT_FOUND), limiting the ability to trace upstream DNS infrastructure.
While the available data confirm active impersonation of Facebook and a high risk rating, the exact payload or credential‑collection mechanisms employed by the site remain unverified, as no detailed page content analysis is provided. Defenders should therefore treat the domain as hostile: block it at perimeter firewalls, DNS resolvers, and web proxies; add it to internal URL filtering and threat‑intel feeds; and monitor for any outbound connections to the associated IP address.
Datenabdeckung13 recorded checks
Erkenntnisse zur Netzwerksicherheit
Pipeline zur Reaktion auf Sicherheitsbedrohungen
Status der öffentlichen Sperrliste
Technologien · 6 identified
Blogger is a blog-publishing service that allows multi-user blogs with time-stamped entries.
www.blogger.com 100 % KonfidenzJava is a class-based, object-oriented programming language that is designed to have as few implementation dependencies as possible.
java.com 100 % KonfidenzOpenGSE is a test suite used for testing servlet compliance. It is deployed by using WAR files that are deployed on the server engine.
code.google.com 100 % KonfidenzGoogle AdSense is a program run by Google through which website publishers serve advertisements that are targeted to the site content and audience.
www.google.com 100 % KonfidenzHTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org 100 % KonfidenzVirusTotal-Analyse
Analyse der Website-Konfiguration
Nachweise und externe BerichteIndependent lookups and source reports
Victim safety and official reportingImmediate actions and verified reporting channels
Wenn Sie Kontoanmeldeinformationen, persönliche oder Zahlungsinformationen eingegeben oder eine Datei von dieser Domain heruntergeladen haben, ergreifen Sie sofort Maßnahmen. Nachfolgend finden Sie Ressourcen, die Ihnen helfen, den Vorfall zu melden und sich zu schützen.
Melden Sie sich bei Ihren örtlichen Behörden
Wählen Sie Ihr Land aus, um Offizielle Kontakte im Bereich Cyberkriminalität oder einen Beschwerdeentwurf erstellen → zu erhalten.