jj-facebook.blogspot.com is currently listed on a security blocklist and is actively blocked by PhishDestroy. The subdomain resolves to the IP address 142.251.13.132, which belongs to Google’s public cloud infrastructure. Registration metadata shows the domain was created through Google LLC, confirming that the hosting provider is Google. No nameserver information is available (NS_NOT_FOUND), which is consistent with Blogger‑hosted subdomains that inherit Google’s DNS configuration.
VirusTotal analysis reports that 7 of 91 scanned security vendors have flagged the domain as malicious, indicating a non‑trivial level of confidence in its abusive nature. The blocklist presence, combined with the multi‑vendor detections, classifies the domain as a high‑risk generic phishing vector, even though the specific page content has not been publicly disclosed. At present, no HTTPS certificate details, HTTP response codes, or page title information have been observed, leaving the exact phishing payload unknown. Defenders should treat the domain as hostile: network perimeter filters, DNS resolvers, and web proxies should deny any resolution to the IP or the full hostname.
Continuous monitoring of the IP range for additional suspicious subdomains is advised, as attackers often reuse cloud‑hosted infrastructure. Organizations using Google Workspace or Blogger platforms should verify that internal users are not being redirected to this subdomain, and incident response teams should collect any logs that reference connections to 142.251.13.132 for further forensic analysis. Because the domain remains active, periodic re‑scanning with VirusTotal or similar services is recommended to detect any changes in detection counts.