# fbiform.org — SUSPICIOUS > Beware: fbiform.org is a fake Facebook form phishing site with 0/95 VirusTotal detections. Check the full report now to stay protected. ## Summary PhishDestroy identifies active phishing operations targeting Facebook users via the domain fbiform.org, a malicious site posing as a legitimate form submission portal. This domain carries a confirmed threat classification as a generic phishing vector, with potential to harvest sensitive credentials and personal data under false pretenses. The operation remains under ongoing investigation but is currently active and propagating across unsuspecting user networks. Users interacting with this domain risk unauthorized account access, data compromise, and identity theft due to its deceptive interface mimicking genuine Facebook functionality. This domain was flagged with zero detections out of 95 engines on VirusTotal, indicating it has evaded immediate automated detection despite its malicious intent. It resolves to IP address 104.21.16.144 and operates under a valid SSL certificate issued by Let's Encrypt, enhancing its credibility and reducing browser warnings. The domain was registered through PDR Ltd. d/b/a PublicDomainRegistry.com and was created on March 21, 2026, suggesting a recently established but rapidly deployed threat infrastructure. As of current analysis, there is no evidence of inclusion on major blocklists or reputational databases, allowing the campaign to persist undetected by traditional perimeter defenses. To mitigate exposure to this threat, users should immediately block the domain fbiform.org at the network or host level and avoid accessing it through any browser or application. Organizations are advised to update firewall rules, DNS filters, and endpoint protection platforms to include this domain and its associated IP (104.21.16.144) in blocklists. Additionally, user awareness training should emphasize verifying form submission URLs, especially those claiming affiliation with Facebook, and reporting suspicious communications to the platform’s official phishing reporting channels. Immediate action is critical to prevent credential harvesting and downstream account compromise. ## Threat Details - Verdict: SUSPICIOUS - Site status: unknown (HTTP ?) ## Domain Intelligence - Registered: 2026-03-21 21:31:22 - Registrar: PDR Ltd. d/b/a PublicDomainRegistry.com - IP: 104.21.16.144 ## Detection Status - VirusTotal: 0 vendors flagged - Google Safe Browsing: clean - Blocklists: 0 hits ## Evidence - Cloudflare Radar: https://radar.cloudflare.com/domains/fbiform.org - PhishDestroy: https://phishdestroy.io/domain/fbiform.org/ - LLM endpoint: https://phishdestroy.io/domain/fbiform.org/llm.txt ## If You Visited This Site 1. Change any passwords you may have entered 2. Enable 2FA on all related accounts 3. Monitor your accounts for unauthorized activity 4. Report to: FBI IC3, Europol, local authorities --- Report by PhishDestroy | https://phishdestroy.io/domain/fbiform.org/ Last updated: 2026-04-07