Analysis of the domain eu-facebook.blogspot.com indicates an active phishing campaign impersonating Facebook login pages, as suggested by the domain naming convention and confirmed by its classification in threat intelligence sources. The domain resolves to IP address 142.251.110.132, which is associated with Google LLC infrastructure, consistent with its registration through the same entity. This alignment with Google's hosting services suggests the use of Blogspot, a common platform for low-cost phishing operations due to its accessibility and perceived legitimacy. As of July 31, 2026, the domain remains active and is flagged by one security blocklist, with PhishDestroy currently blocking access.
VirusTotal reports that 8 out of 91 security vendors detect the domain as malicious, providing additional corroboration of its phishing nature. Notably, the domain lacks configured nameservers, which may indicate an attempt to evade detection or a misconfiguration in the phishing infrastructure. Defenders should treat this domain as high-risk due to its active status, impersonation of a major social media platform, and detection by multiple security vendors. The absence of nameservers does not diminish the threat, as the domain remains resolvable and operational.
Network-level blocking of the IP 142.251.110.132 and the domain itself is recommended for organizations seeking to prevent credential theft or unauthorized access attempts. Monitoring for similar Blogspot-based domains using variations of 'facebook' or other high-value brand names may help identify related campaigns. Given the domain's registration through Google LLC, defenders may also consider reporting the abuse to the registrar to facilitate takedown efforts. While the exact content of the phishing page has not been analyzed, the domain's structure and detection profile strongly suggest it is designed to harvest user credentials.