Analysis indicates that the domain facebookloging1.blogspot.com is presently active and is being used for credential phishing. The domain is hosted on Google’s Blogger platform, as evidenced by registration through Google LLC, and resolves to the IP address 142.251.14.132, which belongs to Google’s infrastructure. The lack of publicly visible nameserver records (NS_NOT_FOUND) suggests that the underlying DNS configuration is either obfuscated or not exposed through standard queries, a tactic sometimes employed to hinder attribution.
VirusTotal reports that 11 of 91 security vendors have flagged the domain, demonstrating that a subset of threat intelligence engines have identified malicious characteristics, while the remaining scanners have not raised alerts, possibly due to differing heuristics or limited visibility into the site’s content. The domain appears on a single security blocklist and is explicitly blocked by PhishDestroy, confirming that at least one dedicated anti‑phishing service has taken remediation action against it. No additional evidence such as page titles, SSL certificate details, HTTP response codes, or Safe Browsing verdicts is available in the current dataset, leaving the exact visual or functional aspects of the site unverified.
Defenders should continue to block traffic to this domain at network perimeter devices, update proxy and DNS filtering rules, and monitor for any outbound requests to the associated Google IP range that may indicate compromised browsers or automated tools attempting to reach the phishing page. Incident response teams should also consider enriching endpoint telemetry with the observed IP address and domain to improve detection of attempted credential harvesting attempts originating from this infrastructure.