On July 29, 2026, the domain facebook-germany.blogspot.com was identified as an active generic phishing infrastructure. The domain resolves to the IPv4 address 142.251.13.132, which is associated with Google’s hosting services. Registration data indicates the domain was created through Google LLC, and the name server information is currently unavailable (NS_NOT_FOUND).
VirusTotal analysis shows that 10 out of 91 security vendors have flagged the domain, confirming that multiple detection engines recognize it as malicious. The domain is listed on a single security blocklist and has been explicitly blocked by the PhishDestroy mitigation service, reinforcing its classification as a high‑risk phishing vector. While the specific content hosted on the site has not been publicly disclosed, the combination of vendor detections, blocklist inclusion, and active blocking suggests a functional phishing campaign targeting users who might be misled by the "facebook-germany" sub‑domain.
Defenders should continue to enforce deny‑list rules for the resolved IP address and monitor DNS queries for the domain to prevent accidental resolution within corporate networks. Additional precautionary measures include updating email security gateways to flag URLs containing "facebook-germany.blogspot.com" and ensuring that web filtering solutions reference the current blocklist entries. Ongoing analysis is recommended to capture any changes in page content, SSL certificate details, or additional hosting modifications that could affect the threat landscape.