facebook-psm[.]blogspot[.]ru
“Facebook”
facebook-psm.blogspot.ru — Não verificado. Representação da marca: Facebook; Tipo de golpe: Social Media Phishing. Resumo das evidências: VirusTotal 15/91 (ADMINUSLabs, Criminal IP, alphaMountain.ai, BitDefender, Chong Lua Dao); CF Radar malicious; PhishDestroy score 95/100. Registrador: GOOGLE (ASN: 15169).
A análise detalhada do PhishDestroy AI permanece em inglês para preservar o registro forense original.
The domain facebook-psm.blogspot.ru is currently active and has been classified as a high‑risk brand‑impersonation site targeting Facebook. Intelligence sources list the domain on two reputable security blocklists, PhishDestroy and PhishingDB, confirming that it is being used to deceive users. The page title returned by the server is simply “Facebook”, which aligns with the declared impersonation of the Facebook brand.
Infrastructure analysis shows the domain is registered through Google, using ASN 15169, and resolves to IP address 142.250.185.97, which belongs to Google LLC in the United States. The host presents a valid SSL certificate issued by Google Trust Services under the WE2 profile, indicating that TLS termination is performed by the same provider that hosts the site. Detected technologies include Blogger, Java, Python, OpenGSE, and HTTP/3, suggesting a standard blog platform enhanced with server‑side scripting.
VirusTotal has flagged the domain on 13 of 95 scanned security vendors, providing additional evidence of malicious intent. The HTTP response is a 302 redirect, a common technique for steering victims to credential‑collection pages after an initial landing. Although the page title is known, the actual content has not been captured, leaving the specifics of the phishing flow uncertain. The domain’s presence on multiple blocklists and the multi‑vendor detection rate support a high confidence rating for phishing activity.
Defenders should immediately block traffic to facebook-psm.blogspot.ru at network perimeter and email gateways, and consider adding the IP 142.250.185.97 to deny lists where appropriate. Continuous monitoring of DNS queries for this domain is advised, as the infrastructure could be repurposed for additional malicious campaigns. Threat‑intel teams should share indicators of compromise with peer organizations to accelerate detection and containment.
Inteligência de segurança de rede
Pipeline de resposta a ameaças
Status da lista de bloqueios pública
Tecnologias · 5 identified
Third major version of HTTP protocol, built on QUIC for faster, more reliable connections.
Análise do VirusTotal
Evidências arquivadas
Evidências e relatórios externos
Você foi afetado por este site?
Se você inseriu credenciais de conta, informações pessoais ou de pagamento, ou baixou um arquivo deste domínio, tome medidas imediatas. Abaixo estão os recursos para ajudá-lo a relatar o incidente e se proteger.
Notifique as autoridades locais
Selecione seu país para obter contactos oficiais do cibercrime ou crie um rascunho de reclamação →.
Verificar qualquer domínio
Análise de ameaças usando lista de bloqueio armazenada, WHOIS, DNS e evidências de verificação pública
Digitalize agoraDenunciar phishing
Envie domínios suspeitos para nosso banco de dados de ameaças — proteja a comunidade
DenunciarFeed de ameaças em tempo real
Relatórios recentes de phishing e alterações de disponibilidade observadas
MonitorarMantenha-se informado, mantenha-se seguro
Monitore ameaças em tempo real ou conteste esta listagem caso acredite que se trate de um falso positivo