This domain, facebook1019key.blogspot.com, is flagged as an active high-risk phishing site targeting Facebook credentials. Analysis indicates the domain is hosted on Google LLC infrastructure, resolving to IP address 142.251.110.132, which is associated with legitimate Google services but is being abused for malicious purposes. The domain is currently active and has been blocked by PhishDestroy, appearing on at least one security blocklist. VirusTotal reports that 8 out of 91 security vendors detect this domain as malicious, providing further evidence of its phishing nature.
Infrastructure analysis reveals the domain lacks configured nameservers, a common tactic to evade detection or complicate takedown efforts. The use of a Blogspot subdomain suggests an attempt to exploit a trusted platform to lend credibility to the phishing campaign. No specific phishing kit or brand impersonation details beyond the Facebook reference in the domain name are confirmed at this time, though the domain structure strongly implies credential harvesting targeting Facebook users. Defenders should treat this domain as a confirmed phishing threat.
Recommended actions include blocking the domain at the DNS or proxy level, updating endpoint protection signatures, and alerting users to avoid interaction. The domain remains active as of July 30, 2026, and further monitoring is advised to track any changes in hosting or infrastructure. Given the lack of nameserver configuration, additional scrutiny of related subdomains or IP-based indicators may be warranted to identify connected malicious activity.