invoice-partner-meta-for-business[.]surge[.]sh
“Meta Privacy Center - Community Standards & Policies”
invoice-partner-meta-for-business.surge.sh — Conteúdo indisponível. Representação da marca: Facebook. Resumo das evidências: VirusTotal 14/95 (ADMINUSLabs, alphaMountain.ai, BitDefender, CyRadar, ESET); URLScan malicious verdict; CF Radar malicious; PhishDestroy score 92/100. Registrador: Surge.sh.
A análise detalhada do PhishDestroy AI permanece em inglês para preservar o registro forense original.
invoice-partner-meta-for-business.surge.sh was flagged by multiple security vendors as a phishing infrastructure targeting Meta users. The only publicly observed attribute is the HTML title "Meta Privacy Center - Community Standards & Policies", suggesting an attempt to masquerade as an official Meta privacy portal. The domain is registered through the Surge.sh service and delegated to the authoritative name servers ns1.surge.sh and ns2.surge.sh. DNS resolution points to 188.166.132.94, an address owned by DigitalOcean, LLC (AS14061) and geolocated to the Netherlands.
HTTPS connections present a Sectigo Limited RSA Domain Validation Secure Server CA certificate, a standard DV certificate that supplies encryption but no brand assurance. HTTP requests return a 404 status code, and the site has been taken offline, which prevents direct content analysis. VirusTotal records indicate that 14 of 95 scanned security vendors flagged the domain, reinforcing suspicion of malicious intent. The domain is listed on at least one external blocklist and is actively blocked by PhishDestroy, confirming that threat‑intelligence feeds recognize it as a phishing vector.
Current evidence is limited to infrastructure data and the observed page title; the actual landing page content, payloads, or user‑interaction mechanisms remain unknown due to the offline status. Defenders should immediately block the domain and its hosting IP, incorporate the host into network‑level deny lists, and monitor for any resurgence of the domain or related Surge.sh sub‑domains. Adding the IP address to sinkhole or threat‑intel platforms can aid in early detection of re‑use. Continuous observation of the AS14061 range is advised, as the host may be repurposed for future phishing campaigns.
Inteligência de segurança de rede
Pipeline de resposta a ameaças
Status da lista de bloqueios pública
Análise do VirusTotal
Evidências arquivadas
Evidências e relatórios externos
Você foi afetado por este site?
Se você inseriu credenciais de conta, informações pessoais ou de pagamento, ou baixou um arquivo deste domínio, tome medidas imediatas. Abaixo estão os recursos para ajudá-lo a relatar o incidente e se proteger.
Notifique as autoridades locais
Selecione seu país para obter contactos oficiais do cibercrime ou crie um rascunho de reclamação →.
Verificar qualquer domínio
Análise de ameaças usando lista de bloqueio armazenada, WHOIS, DNS e evidências de verificação pública
Digitalize agoraDenunciar phishing
Envie domínios suspeitos para nosso banco de dados de ameaças — proteja a comunidade
DenunciarFeed de ameaças em tempo real
Relatórios recentes de phishing e alterações de disponibilidade observadas
MonitorarMantenha-se informado, mantenha-se seguro
Monitore ameaças em tempo real ou conteste esta listagem caso acredite que se trate de um falso positivo