facebook-psm[.]blogspot[.]ru
“Facebook”
facebook-psm.blogspot.ru — Belum terverifikasi. Peniruan identitas merek: Facebook; Jenis penipuan: Social Media Phishing. Ringkasan bukti: VirusTotal 15/91 (ADMINUSLabs, Criminal IP, alphaMountain.ai, BitDefender, Chong Lua Dao); CF Radar malicious; PhishDestroy score 95/100. Registrar: GOOGLE (ASN: 15169).
Analisis terperinci PhishDestroy AI di bawah tetap berbahasa Inggris untuk menjaga catatan forensik asli.
The domain facebook-psm.blogspot.ru is currently active and has been classified as a high‑risk brand‑impersonation site targeting Facebook. Intelligence sources list the domain on two reputable security blocklists, PhishDestroy and PhishingDB, confirming that it is being used to deceive users. The page title returned by the server is simply “Facebook”, which aligns with the declared impersonation of the Facebook brand.
Infrastructure analysis shows the domain is registered through Google, using ASN 15169, and resolves to IP address 142.250.185.97, which belongs to Google LLC in the United States. The host presents a valid SSL certificate issued by Google Trust Services under the WE2 profile, indicating that TLS termination is performed by the same provider that hosts the site. Detected technologies include Blogger, Java, Python, OpenGSE, and HTTP/3, suggesting a standard blog platform enhanced with server‑side scripting.
VirusTotal has flagged the domain on 13 of 95 scanned security vendors, providing additional evidence of malicious intent. The HTTP response is a 302 redirect, a common technique for steering victims to credential‑collection pages after an initial landing. Although the page title is known, the actual content has not been captured, leaving the specifics of the phishing flow uncertain. The domain’s presence on multiple blocklists and the multi‑vendor detection rate support a high confidence rating for phishing activity.
Defenders should immediately block traffic to facebook-psm.blogspot.ru at network perimeter and email gateways, and consider adding the IP 142.250.185.97 to deny lists where appropriate. Continuous monitoring of DNS queries for this domain is advised, as the infrastructure could be repurposed for additional malicious campaigns. Threat‑intel teams should share indicators of compromise with peer organizations to accelerate detection and containment.
Intelijen Keamanan Jaringan
Alur Tanggapan Ancaman Pipeline
Status Daftar Blokir Publik
Teknologi · 5 identified
Third major version of HTTP protocol, built on QUIC for faster, more reliable connections.
Analisis VirusTotal
Bukti Terarsip
Bukti & Laporan Eksternal
Apakah Anda Terpengaruh oleh Situs Ini?
Jika Anda memasukkan kredensial akun, informasi pribadi atau pembayaran, atau mengunduh file dari domain ini, segera ambil tindakan. Di bawah ini adalah sumber daya untuk membantu Anda melaporkan insiden tersebut dan melindungi diri Anda sendiri.
Laporkan kepada Pihak Berwenang di Daerah Anda
Pilih negara Anda untuk mendapatkan kontak resmi kejahatan dunia maya, atau membuat draf pengaduan →.
Periksa Domain Apa Pun
Analisis ancaman menggunakan daftar blokir yang disimpan, WHOIS, DNS, dan bukti pemindaian publik
Pindai SekarangLaporkan Phishing
Laporkan domain yang mencurigakan ke basis data ancaman kami — lindungi komunitas
LaporanPemberitahuan Ancaman Real-Time
Laporan phishing terbaru dan perubahan ketersediaan yang diamati
PantauTetap Terinformasi, Tetap Aman
Pantau ancaman secara langsung atau ajukan keberatan terhadap daftar ini jika Anda yakin ini merupakan false positive