The domain facebookahla.blogspot.com is currently active and classified as a high‑risk generic phishing site. Registration data shows the domain was created through Google LLC, indicating it is a Blogspot sub‑domain that leverages Google’s hosting infrastructure. DNS resolution points to IP address 142.251.14.132, an address owned by Google, confirming the use of legitimate cloud resources to mask malicious activity.
VirusTotal scans have identified the domain as malicious in 7 of 91 security vendor detections, providing independent confirmation of its threat status. The domain appears on a single public security blocklist and is explicitly blocked by the PhishDestroy feed, demonstrating that at least one reputable anti‑phishing service has taken action against it. Nameserver information is reported as NS_NOT_FOUND, which is typical for Blogspot‑hosted sites that rely on Google’s default DNS configuration.
No additional intelligence such as SSL certificate details, HTTP response codes, Safe Browsing verdicts, OTX references, or page‑title analysis is presently available, leaving those aspects of the infrastructure unverified. Defenders should treat the domain as hostile: network‑level filters should block outbound and inbound traffic to the domain and its resolved IP, security appliances should flag any URLs containing the domain, and endpoint protection should monitor for attempts to access the site. Continuous monitoring of threat intelligence feeds for new detections or blocklist additions is recommended, as the domain’s use of reputable hosting may enable rapid re‑deployment or slight variations that evade static blocklists.