facebook-psm[.]blogspot[.]ru
“Facebook”
facebook-psm.blogspot.ru — असत्यापित. ब्रांड प्रतिरूपण: Facebook; घोटाले का प्रकार: Social Media Phishing. साक्ष्य सारांश: VirusTotal 15/91 (ADMINUSLabs, Criminal IP, alphaMountain.ai, BitDefender, Chong Lua Dao); CF Radar malicious; PhishDestroy score 95/100. रजिस्ट्रार: GOOGLE (ASN: 15169).
मूल फॉरेंसिक रिकॉर्ड सुरक्षित रखने के लिए नीचे का विस्तृत PhishDestroy AI विश्लेषण अंग्रेज़ी में रखा गया है।
The domain facebook-psm.blogspot.ru is currently active and has been classified as a high‑risk brand‑impersonation site targeting Facebook. Intelligence sources list the domain on two reputable security blocklists, PhishDestroy and PhishingDB, confirming that it is being used to deceive users. The page title returned by the server is simply “Facebook”, which aligns with the declared impersonation of the Facebook brand.
Infrastructure analysis shows the domain is registered through Google, using ASN 15169, and resolves to IP address 142.250.185.97, which belongs to Google LLC in the United States. The host presents a valid SSL certificate issued by Google Trust Services under the WE2 profile, indicating that TLS termination is performed by the same provider that hosts the site. Detected technologies include Blogger, Java, Python, OpenGSE, and HTTP/3, suggesting a standard blog platform enhanced with server‑side scripting.
VirusTotal has flagged the domain on 13 of 95 scanned security vendors, providing additional evidence of malicious intent. The HTTP response is a 302 redirect, a common technique for steering victims to credential‑collection pages after an initial landing. Although the page title is known, the actual content has not been captured, leaving the specifics of the phishing flow uncertain. The domain’s presence on multiple blocklists and the multi‑vendor detection rate support a high confidence rating for phishing activity.
Defenders should immediately block traffic to facebook-psm.blogspot.ru at network perimeter and email gateways, and consider adding the IP 142.250.185.97 to deny lists where appropriate. Continuous monitoring of DNS queries for this domain is advised, as the infrastructure could be repurposed for additional malicious campaigns. Threat‑intel teams should share indicators of compromise with peer organizations to accelerate detection and containment.
नेटवर्क सुरक्षा इंटेलिजेंस
धमकी प्रतिक्रिया पाइपलाइन
सार्वजनिक ब्लॉकलिस्ट स्थिति
तकनीकें · 5 identified
Third major version of HTTP protocol, built on QUIC for faster, more reliable connections.
वायरसटोटल विश्लेषण
संग्रहीत साक्ष्य
साक्ष्य और बाहरी रिपोर्टें
क्या आप इस साइट से प्रभावित हुए?
यदि आपने खाता क्रेडेंशियल, व्यक्तिगत या भुगतान जानकारी दर्ज की है, या इस डोमेन से कोई फ़ाइल डाउनलोड की है, तो तुरंत कार्रवाई करें। घटना की रिपोर्ट करने और अपनी सुरक्षा करने में आपकी सहायता के लिए नीचे संसाधन दिए गए हैं।
अपने स्थानीय अधिकारियों को रिपोर्ट करें
आधिकारिक साइबर अपराध संपर्क, या एक शिकायत ड्राफ्ट बनाएं → प्राप्त करने के लिए अपना देश चुनें।
किसी भी डोमेन की जाँच करें
संग्रहीत ब्लॉकलिस्ट, WHOIS, DNS और सार्वजनिक स्कैन साक्ष्य का उपयोग करके खतरे का विश्लेषण
अभी स्कैन करेंफ़िशिंग की रिपोर्ट करें
संदिग्ध डोमेन हमारे थ्रेट डेटाबेस में जमा करें — समुदाय की सुरक्षा करें
रिपोर्ट करेंसीधा खतरा फीड
हाल की फ़िशिंग रिपोर्टें और उपलब्धता में परिवर्तन देखे गए
निगरानी करेंजानकारी में रहें, सुरक्षित रहें
लाइव खतरों की निगरानी करें या यदि आपको लगता है कि यह एक गलत सकारात्मक है तो इस लिस्टिंग को चुनौती दें।