eu-facebook.blogspot.com is a tenant hostname on Google LLC, not a separately registered domain. PhishDestroy first observed the hostname on Jul 31, 2026. The hostname explicitly references Facebook; stored content metadata identifies the same apparent target. The captured page title is “Facebook”. Page analysis recorded additional brand references to Google. Stored page analysis classifies the content as credential phishing. Current evidence score: 100/100 (critical).
Positive findings are stored from 3 sources: VirusTotal, Phishunt, and URLScan. VirusTotal recorded 20 detections among 91 engines: Criminal IP, alphaMountain.ai, BitDefender, Chong Lua Dao, CyRadar, ESET, Emsisoft, Forcepoint ThreatSeeker, Fortinet, G-Data, Gridinsoft, Kaspersky, LevelBlue, Lionic, MalwareURL, Netcraft, Sophos, URLQuery, VIPRE, Webroot on Aug 8, 2026 at 02:17 UTC. Phishunt listed the hostname in the separate external-blocklist snapshot on Aug 8, 2026 at 10:20 UTC. URLScan returned a malicious verdict with score 100; scan metadata linked the capture to Facebook and assigned phishing as its category on Aug 1, 2026 at 03:30 UTC. Non-positive and contextual checks: Google Safe Browsing returned no flag on Jul 31, 2026 at 12:26 UTC.
HTTP 200 was recorded on Aug 8, 2026 at 10:00 UTC. Google LLC is the hosting platform for this tenant, not its registrar. At collection time, the hostname resolved to 142.251.110.132 on AS15169 (Google LLC). The recorded endpoint location is Mountain View, US. The IP and ASN identify shared Google LLC infrastructure, not the tenant operator. The stored server header is GSE. DOM analysis on Jul 31, 2026 at 14:20 UTC returned 90/100. The evidence archive retains 2 visual captures from PhishDestroy and URLScan. The platform TLS certificate was issued by Google Trust Services with validity through Sep 21, 2026; checked Jul 31, 2026 at 13:02 UTC.
The content indicators and 3 positive source findings support the current Facebook-themed credential phishing classification.