customer-support-system-customer-care-station[.]pages[.]dev
“Facebook – log in or sign up”
customer-support-system-customer-care-station.pages.dev — Contenuto non disponibile. Simulazione del marchio: Facebook; Tipo di truffa: Brand Impersonation. Riepilogo delle prove: VirusTotal 11/93 (ADMINUSLabs, BitDefender, DNS8, Emsisoft, Fortinet); Google Safe Browsing flagged; PhishDestroy score 88/100. Registrar: Cloudflare.
L’analisi dettagliata di PhishDestroy AI resta in inglese per preservare il rapporto forense originale.
Analysis of the domain customer-support-system-customer-care-station.pages.dev indicates a high-risk brand impersonation campaign targeting Facebook users. The domain was registered on March 3, 2026, through Cloudflare, Inc., and currently resolves to IP 157.240.8.35, hosted on AS13335 (Cloudflare, Inc.) in the United States. Nameservers archer.ns.cloudflare.com and meadow.ns.cloudflare.com further confirm Cloudflare as the infrastructure provider. The domain's HTTP status is 403 (Forbidden), though it previously displayed the page title 'Facebook – log in or sign up,' directly aligning with the identified scam type of brand impersonation targeting Facebook.
Detection data reveals the domain appears on at least one security blocklist, with Google Safe Browsing flagging it for social engineering. Eleven of 93 security vendors on VirusTotal have detected the domain as malicious. Trust scores from Scamadviser and Gridinsoft are 1/100 and 0/100, respectively, indicating negligible legitimacy. The SSL certificate is issued by Google Trust Services (WE1), a common feature in both legitimate and malicious Cloudflare-hosted domains.
Infrastructure analysis reveals the use of HTTP/3 and HSTS, technologies often employed to enhance performance and security, which may also serve to evade detection or lend an appearance of legitimacy. The domain was taken offline following identification, though its prior activity and detection metrics suggest a deliberate attempt to deceive users into divulging credentials. Defenders should treat this domain as compromised and block all associated IPs, particularly 157.240.8.35, within network security controls. Monitoring for similar patterns, such as Cloudflare-hosted domains with brand-related subdomains, is recommended to preempt further impersonation attempts.
Pipeline di risposta alle minacce
Stato della lista di blocco pubblica
Informazioni forensi
Tecnologie · 3 identified
HTTP Strict Transport Security — forces browsers to use HTTPS connections only.
Web infrastructure and security company providing CDN, DDoS mitigation, and DNS services.
www.cloudflare.comThird major version of HTTP protocol, built on QUIC for faster, more reliable connections.
Analisi di VirusTotal
Prove archiviate
Analisi delle prestazioni del sito
Google PageSpeed Insights — mobile performance audit of customer-support-system-customer-care-station.pages.dev · checked Apr 11, 2026
Dati e relazioni esterne
Questo sito ti ha influenzato in qualche modo?
Se hai inserito credenziali dell'account, informazioni personali o di pagamento oppure hai scaricato un file da questo dominio, agisci immediatamente. Di seguito sono riportate le risorse per aiutarti a segnalare l'incidente e proteggerti.
Segnalalo alle autorità locali
Seleziona il tuo Paese per ottenere contatti ufficiali del crimine informatico o creare una bozza di reclamo →.
Verifica qualsiasi dominio
Analisi delle minacce utilizzando blocklist archiviate, WHOIS, DNS e prove di scansione pubblica
Scansiona oraSegnala un tentativo di phishing
Segnala i domini sospetti al nostro database delle minacce — proteggi la comunità
SegnalaFeed in tempo reale sulle minacce
Segnalazioni recenti di phishing e modifiche osservate della disponibilità
MonitoraRimani informato, rimani al sicuro
Controlla le minacce in tempo reale oppure contesta questa segnalazione se ritieni che si tratti di un falso positivo