invited-for-bluefree[.]surge[.]sh
“Meta Verified – Facebook”
invited-for-bluefree.surge.sh — Contenido no disponible. Suplantación de marca: Facebook; Tipo de estafa: Brand Impersonation. Resumen de las pruebas: VirusTotal 14/91 (alphaMountain.ai, BitDefender, CyRadar, Emsisoft, Forcepoint ThreatSeeker); URLScan malicious verdict; CF Radar malicious; PhishDestroy score 92/100. Registrador: Surge.sh.
El análisis detallado de PhishDestroy AI se mantiene en inglés para conservar el registro forense original.
This domain, invited-for-bluefree.surge.sh, is flagged as a high-risk brand impersonation threat targeting Facebook. Analysis indicates the site mimics Meta Verified, a premium verification service, to deceive users into submitting login credentials or personal information. No crypto drainer or malware payloads have been observed in initial scans, but the page structure and visual elements closely resemble official Facebook properties, including the use of Meta branding and Facebook color schemes. The domain operates under the guise of account verification, a common tactic for credential theft campaigns. Infrastructure analysis reveals the domain is hosted on Surge.sh, a free static web publishing service, and resolves to IP 159.203.50.177, located in Canada under AS14061 (DigitalOcean, LLC). The SSL certificate is issued by Sectigo Limited (Sectigo Public Server Authentication CA DV R36), a legitimate but frequently abused certificate authority. VirusTotal detection shows 14 out of 95 security vendors flag the domain as malicious, while it appears on one security blocklist. No creation date is publicly available due to Surge.sh's ephemeral hosting model, but the domain remains active and unlisted by Google Safe Browsing at the time of analysis. Current status indicates the domain is still operational, though it has been blocked by at least one security provider. Response actions should include immediate blacklisting, DNS sinkholing for the resolved IP, and monitoring for related subdomains or redirect chains. The remaining risk is elevated due to the domain's active status, low detection rate, and direct impersonation of a high-value brand. Users are advised to verify URLs against official Facebook domains, avoid interacting with unsolicited verification prompts, and report suspicious links to their security teams for further investigation.
Inteligencia de seguridad de red
Proceso de respuesta ante amenazas Pipeline
Estado de la lista de bloqueados pública
Análisis de VirusTotal
Datos y informes externos
¿Te ha afectado esta página web?
Si ingresó credenciales de cuenta, información personal o de pago, o descargó un archivo de este dominio, tome medidas inmediatas. A continuación encontrará recursos que le ayudarán a informar el incidente y protegerse.
Informa a las autoridades locales
Seleccione su país para obtener contactos oficiales de cibercrimen o crear un borrador de queja →.
Comprobar cualquier dominio
Análisis de amenazas utilizando listas de bloqueo almacenadas, WHOIS, DNS y evidencia de escaneo público
Escanear ahoraDenunciar un intento de phishing
Envía los dominios sospechosos a nuestra base de datos de amenazas: protege a la comunidad
DenunciarFlujo de amenazas en tiempo real
Informes de phishing recientes y cambios de disponibilidad observados
MonitorizarMantente informado, mantente a salvo
Supervisa las amenazas en tiempo real o impugna esta entrada si crees que se trata de un falso positivo.