# facebookform.vercel.app — MALICIOUS > PhishDestroy warns: facebookform.vercel.app is a crypto drainer impersonating Facebook, flagged by 16 of 95 VirusTotal vendors. ## Summary PhishDestroy identifies active brand impersonation threat associated with domain facebookform.vercel.app. This malicious site specifically mimics Facebook login interfaces to harvest user credentials and deploy cryptocurrency drainers. The domain has been classified as an elevated-risk threat due to its active deception tactics targeting Facebook users. This domain was flagged by 16 of 95 VirusTotal security vendors, indicating significant malicious detection across multiple scanning engines. The domain resolves to IP address 64.29.17.131 and operates through Vercel Inc. registrar infrastructure. The SSL certificate provided by Google Trust Services enables secure appearance while concealing malicious functionality. VirusTotal detection represents 16.8% malicious identification rate with additional blocklist contributions from multiple threat intelligence platforms. Current status remains active with persistent threat operation. PhishDestroy strongly recommends immediate blocking of this domain at network and endpoint levels. Users should verify any Facebook login pages using PhishDestroy's verification tools before entering credentials. Organizations should implement browser security policies to prevent access to this malicious domain and similar impersonation sites. Enhanced monitoring of the associated IP address (64.29.17.131) is advised for network defense teams. ## Threat Details - Verdict: MALICIOUS - Site status: unknown (HTTP ?) - Target brand: Facebook ## Domain Intelligence - Registrar: Vercel Inc. - IP: 64.29.17.131 ## Detection Status - VirusTotal: 16 vendors flagged - Google Safe Browsing: clean - Blocklists: 0 hits ## Evidence - Cloudflare Radar: https://radar.cloudflare.com/scan/9fca3871-56a7-49e2-8788-c730da2d65c1 - PhishDestroy: https://phishdestroy.io/domain/facebookform.vercel.app/ - LLM endpoint: https://phishdestroy.io/domain/facebookform.vercel.app/llm.txt ## If You Visited This Site 1. Change any passwords you may have entered 2. Enable 2FA on all related accounts 3. Monitor your accounts for unauthorized activity 4. Report to: FBI IC3, Europol, local authorities --- Report by PhishDestroy | https://phishdestroy.io/domain/facebookform.vercel.app/ Last updated: 2026-03-22