Analysis of the domain facebook-22.blogspot.com indicates that it is actively being used for phishing. The domain resolves to the IP address 142.251.110.132, which belongs to the infrastructure operated by Google LLC, the registrar listed for the domain. No authoritative nameserver records were returned, suggesting that the domain is hosted on a shared blogging platform rather than on a dedicated name service. VirusTotal has recorded 20 detections out of 91 scanned security vendors, confirming that a significant portion of the scanning community classifies the host as malicious.
The domain is present on three public phishing blocklists and is explicitly blocked by PhishDestroy, OpenPhish, and Phishunt, reinforcing its reputation as a high‑risk phishing resource. The risk rating assigned is high and the operational status remains active as of the report date, July 28 2026. Evidence beyond the listed indicators—such as page content, SSL certificate details, or HTTP response codes—has not been disclosed, leaving those aspects unverified. Defenders should immediately add facebook-22.blogspot.com to deny‑list rules in perimeter firewalls, DNS filtering services, and endpoint web controls.
Continuous monitoring of the associated IP 142.251.110.132 is advised, as the address may serve additional malicious sub‑domains. Organizations using Google‑hosted services should verify that internal URL filtering solutions recognize this domain as malicious to prevent credential harvesting attempts. Given the confirmed detections and blocklist presence, remediation actions should prioritize user awareness messaging and the enforcement of multi‑factor authentication to mitigate potential credential compromise.