The domain facebook-login-page-4g6p.onrender.com is currently active and has been identified as a credential phishing infrastructure targeting Facebook users. The site resolves to IP 216.24.57.7, which is hosted by Render Services Inc., the same entity listed as the registrar. VirusTotal has recorded 14 positive detections out of 91 scanned security vendors, indicating that multiple AV engines recognize malicious behavior. Google Safe Browsing also classifies the URL as social engineering.
The domain is listed on one public blocklist and has been actively blocked by the PhishDestroy service. Nameserver information is unavailable, as the domain returns NS_NOT_FOUND, which may hinder certain DNS‑based mitigation techniques. No additional intelligence such as SSL certificate details, HTTP response codes, page title, or content analysis is presently available, leaving the exact content and tactics of the phishing page unverified.
Defenders should prioritize immediate blocking of the domain at network perimeter and DNS level, add the IP address 216.24.57.7 to blacklists, and monitor for any related activity that may leverage the same hosting infrastructure. Continuous re‑scanning with VirusTotal and other sandbox services is advised to capture potential updates to the payload or hosting. Organizations should also educate users about unsolicited login prompts referencing Facebook, and enforce multi‑factor authentication to mitigate credential theft risk.