facebook-photo5[.]blogspot[.]com
“facebook”
facebook-photo5.blogspot.com — Non verificato. Simulazione del marchio: Facebook; Tipo di truffa: Brand Impersonation. Riepilogo delle prove: VirusTotal 17/91 (Criminal IP, alphaMountain.ai, BitDefender, ESET, Emsisoft); URLScan malicious verdict; 1 external blocklist match (Phishunt); PhishDestroy score 95/100. Registrar: Google Blogger.
L’analisi dettagliata di PhishDestroy AI resta in inglese per preservare il rapporto forense originale.
This domain, facebook-photo5.blogspot.com, is flagged as a high-risk brand impersonation threat targeting Facebook. Analysis indicates the infrastructure is designed to deceive users into believing they are interacting with legitimate Facebook services, likely to harvest login credentials or distribute malicious payloads. The page title explicitly displays 'facebook,' reinforcing the impersonation attempt, though no specific drainer kit signatures have been confirmed at this time. Infrastructure analysis reveals the domain resolves to the IP address 142.250.154.132, which is associated with legitimate services but repurposed for malicious activity. VirusTotal reports 6 out of 95 security vendors have detected this domain as malicious, indicating moderate but not universal recognition of the threat. The SSL certificate is issued by Google Trust Services, providing a false sense of security to potential victims. No registrar details or domain creation date are publicly available due to the use of a subdomain under blogspot.com, which obscures traditional WHOIS data. Google Safe Browsing (GSB) status and blocklist counts are not explicitly provided, but the domain's active exploitation suggests it may not yet be widely blocked. As of the latest verification, facebook-photo5.blogspot.com remains active and continues to host the impersonation content. Users encountering this domain are advised to avoid interaction, particularly entering credentials or downloading files. Organizations should consider implementing network-level blocks for the domain and its associated IP to mitigate exposure. The remaining risk is classified as high due to the domain's active status, the targeted brand's widespread user base, and the potential for credential theft or malware distribution. Continuous monitoring of related infrastructure is recommended to identify evolving threats linked to this campaign.
Pipeline di risposta alle minacce
Stato della lista di blocco pubblica
Tecnologie · 12 identified
WordPress is a free and open-source content management system written in PHP and paired with a MySQL or MariaDB database. Features include a plugin architecture and a template system.
wordpress.org Confidenza al 100%Blogger is a blog-publishing service that allows multi-user blogs with time-stamped entries.
www.blogger.com Confidenza al 100%Java is a class-based, object-oriented programming language that is designed to have as few implementation dependencies as possible.
java.com Confidenza al 100%YouTube is a video sharing service where users can create their own profile, upload videos, watch, like and comment on other videos.
www.youtube.com Confidenza al 100%OpenGSE is a test suite used for testing servlet compliance. It is deployed by using WAR files that are deployed on the server engine.
code.google.com Confidenza al 100%Twitter is a 'microblogging' system that allows you to send and receive short posts called tweets.
twitter.com Confidenza al 100%Simpli.fi is a programmatic advertising and agency management software.
simpli.fi Confidenza al 100%AppNexus is a cloud-based software platform that enables and optimizes programmatic online advertising.
appnexus.com Confidenza al 100%Advertising / conversion-tracking pixel — signals paid marketing activity on this site.
www.advertstream.com Confidenza al 100%Analisi di VirusTotal
Analisi delle prestazioni del sito
Google PageSpeed Insights — mobile performance audit of facebook-photo5.blogspot.com · checked Jul 10, 2026
Dati e relazioni esterne
Questo sito ti ha influenzato in qualche modo?
Se hai inserito credenziali dell'account, informazioni personali o di pagamento oppure hai scaricato un file da questo dominio, agisci immediatamente. Di seguito sono riportate le risorse per aiutarti a segnalare l'incidente e proteggerti.
Segnalalo alle autorità locali
Seleziona il tuo Paese per ottenere contatti ufficiali del crimine informatico o creare una bozza di reclamo →.
Verifica qualsiasi dominio
Analisi delle minacce utilizzando blocklist archiviate, WHOIS, DNS e prove di scansione pubblica
Scansiona oraSegnala un tentativo di phishing
Segnala i domini sospetti al nostro database delle minacce — proteggi la comunità
SegnalaFeed in tempo reale sulle minacce
Segnalazioni recenti di phishing e modifiche osservate della disponibilità
MonitoraRimani informato, rimani al sicuro
Controlla le minacce in tempo reale oppure contesta questa segnalazione se ritieni che si tratti di un falso positivo