सुरक्षा रिपोर्ट पर जाएँ
⚠️
इस डोमेन को दुर्भावनापूर्ण के रूप में चिह्नित किया गया है।
सुरक्षा इंजन एक पहचान की रिपोर्ट कर रहे हैं: 13। अत्यधिक सावधानी बरतें - क्रेडेंशियल या व्यक्तिगत जानकारी दर्ज न करें।
डोमेन सुरक्षा और ख़तरे की आसूचना

facebook-downloader[.]czhyk[.]biz[.]id

“Verify to Continue”

धमकी भरा फैसला गंभीर 89/100 साक्ष्य स्कोर
उपलब्धता असत्यापित वर्तमान पहुंच योग्यता असत्यापित है
वायरस का कुल पता लगाना: 13/91 ब्रांड प्रतिरूपण: Facebook
01/04/2026 Facebook
रिपोर्ट सारांश

facebook-downloader.czhyk.biz.id — असत्यापित. ब्रांड प्रतिरूपण: Facebook; घोटाले का प्रकार: Brand Impersonation. साक्ष्य सारांश: VirusTotal 13/91 (ADMINUSLabs, alphaMountain.ai, BitDefender, ESET, Forcepoint ThreatSeeker); PhishDestroy score 89/100. रजिस्ट्रार: PT JC Indonesia.

मूल फॉरेंसिक रिकॉर्ड सुरक्षित रखने के लिए नीचे का विस्तृत PhishDestroy AI विश्लेषण अंग्रेज़ी में रखा गया है।

साक्ष्य सारांश
आलोचनात्मक
संदर्भ
6F3A7844
स्कोर
89/100

Domain facebook-downloader.czhyk.biz.id is currently under active investigation for engaging in brand impersonation, specifically targeting Facebook users with a counterfeit downloader service. The site is confirmed active and operates under the guise of providing legitimate Facebook content extraction tools, luring victims into entering credentials or downloading malicious payloads. This deception is a direct attempt to exploit user trust in the Facebook brand for credential harvesting or malware distribution.

This domain was flagged by 18 of 95 VirusTotal vendors at the time of analysis, indicating it has evaded immediate detection by most antivirus engines. The domain resolves to IP address 15.235.206.12 and is secured with a Let's Encrypt SSL certificate, which may enhance its perceived legitimacy. The seed identifier 6f3a78 correlates this domain to a broader campaign of brand impersonation scams, though detailed registrar or blocklist data remains unavailable. The lack of detections suggests this threat is either newly deployed or employs sophisticated evasion techniques to bypass initial security scans.

Current status indicates this threat is active and evolving, with potential for escalation if undetected. Users are strongly advised to avoid interacting with this domain or any linked pages, particularly those requesting login credentials or downloads. Conduct a VirusTotal scan of the domain (18/95 detections as of analysis) to verify its status, and report the domain to relevant cybersecurity authorities or blocklist maintainers. Organizations should update firewall rules to block IP 15.235.206.12 and monitor network traffic for connections to this domain or its subdomains. Exercise heightened caution with domains offering free services tied to high-value brands like Facebook, as these are frequent vectors for credential theft and malware delivery.

VirusTotal
VirusTotal
13 det.
DNS Security
1/12
URLScan
यूआरएलस्कैन
TLS प्रमाणपत्र
Let's Encrypt
आयु
5 mo
देखी गई स्थिति
असत्यापित
PhishDestroy
विनाश सूची
सूचीबद्ध
डेटा कवरेज VirusTotal 13 / 91 यूआरएलक्वेरी जाँच नहीं की गई फ़िशस्टैट्स checked — no match recorded ओटीएक्स no community references सीएफ रडार scan completed URLScan capture संग्रहित रिपोर्ट URLScan verdict विश्लेषण पूरा हुआ डीएनएस ब्लॉक 1/12 TLS valid certificate, 89d कौन है 5 mo old स्क्रीनशॉट 2 captures · 2 sources चेन पुनर्निर्देशित करें जांच नहीं की गई
नेटवर्क सुरक्षा इंटेलिजेंस
DNS Provider Blocks 1 / 12
Brand Facebook

धमकी प्रतिक्रिया पाइपलाइन

खोज
Checks
Reports
उपलब्धता
12/14

सार्वजनिक ब्लॉकलिस्ट स्थिति

सहेजा गया कैप्चर

डोमेन इंटेलिजेंस

डोमेन
URLScan Verdict विश्लेषण पूरा हुआ score 0 report ↗
सर्वर / ASN LiteSpeed · AS16276 OVH SAS
IP प्रतिष्ठा abuse score 0/100 0 reports checked 13/08/2026
Registrar (base domain) PT JC Indonesia
IP पता 15.235.206.12 SG
भौगोलिक स्थानSG Singapore, SG
नेटवर्कAS16276 · OVH Singapore PTE. LTD
रिवर्स IPviewdns.info → rapiddns.io →
Registration (base domain)czhyk.biz.id · निर्मित 01/04/2026 (143d)
Elapsed Since First Report 21 days
हम क्या मापते हैं Raw elapsed time since the first stored abuse report. It is not a registrar response-time measurement. Latest observed status: असत्यापित.
प्रत्येक रिपोर्ट में क्या शामिल है संग्रहीत आउटगोइंग-रिपोर्ट रिकॉर्ड उस समय उपलब्ध साक्ष्य का संदर्भ दे सकते हैं, जैसे विक्रेता के फैसले, पंजीकरण डेटा, होस्टिंग विवरण, वर्गीकरण, या स्क्रीनशॉट। यह पृष्ठ किसी प्राप्तकर्ता द्वारा वितरित सटीक पेलोड, रसीद, पावती या कार्रवाई का अनुमान नहीं लगाता है।
तकनीकी विवरणडीएनएस, एसएसएल एसएएन, टाइमस्टैम्प
पहली बार पता चला01/04/2026
IoC Extractionscanned 01/08/20260 wallet · 0 Telegram IoCs
Submitted URLhttp://facebook-downloader.czhyk.biz.id/
नेमसर्वरraina.ns.cloudflare.com
TLS Fingerprint
TLS Observationvalid from 01/04/2026scanned 03/04/2026
पेज शीर्षक
Verify to Continue
TLS प्रमाणपत्र
Valid transport encryption · जारीकर्ता Let's Encrypt · valid for 89 days
तकनीकें · 6 identified
PHP
Programming languages

Server-side scripting language designed for web development.

LiteSpeed
Web servers

High-performance web server compatible with Apache configurations.

Cloudflare
CDN

Web infrastructure and security company providing CDN, DDoS mitigation, and DNS services.

www.cloudflare.com
Font Awesome

Icon font library.

cdnjs
HTTP/3
Miscellaneous

Third major version of HTTP protocol, built on QUIC for faster, more reliable connections.

Detected via क्लाउडफ्लेयर रडार · Wappalyzer engine
इस डोमेन की रिपोर्ट करें सबूत जमा करें और दूसरों की सुरक्षा में मदद करें

वायरसटोटल विश्लेषण

13 / 91 सुरक्षा विक्रेताओं ने इस डोमेन को चिह्नित किया
View on VT
Last analyzed Previous stored snapshot: 13 detections
ADMINUSLabs
alphaMountain.ai
BitDefender
ईएसईटी
Forcepoint ThreatSeeker
Fortinet
G-Data
Gridinsoft
Lionic
Seclookup
सोफोस
VIPRE
वेबरूट

संग्रहीत साक्ष्य

Wayback Machine Snapshot
साक्ष्य समीक्षा के लिए एक ऐतिहासिक स्नैपशॉट उपलब्ध है
View Archive
साइट प्रदर्शन विश्लेषण

Google PageSpeed Insights — mobile performance audit of facebook-downloader.czhyk.biz.id · checked Apr 1, 2026

71
Needs Work
Performance
FCP
4.6s
First Contentful Paint
LCP
4.6s
Largest Contentful Paint
CLS
0
Cumulative Layout Shift
TBT
0ms
Total Blocking Time
SI
5.16s
Speed Index
Powered by Google PageSpeed Insights · Mobile strategy · Scores: 90-100 Good 50-89 Needs Work 0-49 Poor

साक्ष्य और बाहरी रिपोर्टें

क्या आप इस साइट से प्रभावित हुए?

If credentials were compromised, report immediately. Do not engage with recovery scammers.

यदि आपने खाता क्रेडेंशियल, व्यक्तिगत या भुगतान जानकारी दर्ज की है, या इस डोमेन से कोई फ़ाइल डाउनलोड की है, तो तुरंत कार्रवाई करें। घटना की रिपोर्ट करने और अपनी सुरक्षा करने में आपकी सहायता के लिए नीचे संसाधन दिए गए हैं।

यूरोपोल
अपने ईयू देश के लिए आधिकारिक रिपोर्टिंग चैनल ढूंढें
National police directory
रिकवरी ठगों से सावधान रहें! अपराधी जांचकर्ता, वकील या रिकवरी एजेंट होने का नाटक करते हुए पीड़ितों से दोबारा संपर्क कर सकते हैं। अग्रिम शुल्क का भुगतान न करें या क्रेडेंशियल साझा न करें। रिकवरी धोखाधड़ी के बारे में और जानें →

अपने स्थानीय अधिकारियों को रिपोर्ट करें

आधिकारिक साइबर अपराध संपर्क, या एक शिकायत ड्राफ्ट बनाएं → प्राप्त करने के लिए अपना देश चुनें।

97-देश निर्देशिका
एआई-सहायता प्राप्त ड्राफ्ट - घटना विवरण एआई प्रदाता द्वारा संसाधित किया जाता है इसकी स्वयं समीक्षा करें और सबमिट करें

किसी भी डोमेन की जाँच करें

संग्रहीत ब्लॉकलिस्ट, WHOIS, DNS और सार्वजनिक स्कैन साक्ष्य का उपयोग करके खतरे का विश्लेषण

अभी स्कैन करें

फ़िशिंग की रिपोर्ट करें

संदिग्ध डोमेन हमारे थ्रेट डेटाबेस में जमा करें — समुदाय की सुरक्षा करें

रिपोर्ट करें

सीधा खतरा फीड

हाल की फ़िशिंग रिपोर्टें और उपलब्धता में परिवर्तन देखे गए

निगरानी करें

जानकारी में रहें, सुरक्षित रहें

लाइव खतरों की निगरानी करें या यदि आपको लगता है कि यह एक गलत सकारात्मक है तो इस लिस्टिंग को चुनौती दें।

सीधा खतरा फीड इस लिस्टिंग के खिलाफ अपील करें
HTML · IFRAME

इस रिपोर्ट को एम्बेड करें

इस थ्रेट इंटेलिजेंस को अपनी वेबसाइट या ब्लॉग पर साझा करें।

embed.html
<iframe
  src="https://phishdestroy.io/hi/embed/domain/facebook-downloader.czhyk.biz.id"
  title="PhishDestroy threat report for facebook-downloader.czhyk.biz.id"
  width="100%" height="320"
  loading="lazy"
  referrerpolicy="no-referrer"
  sandbox="allow-same-origin allow-popups allow-popups-to-escape-sandbox"
  style="border:0;border-radius:12px;max-width:100%"
></iframe>