customer-support-system-customer-care-station[.]pages[.]dev
“Facebook – log in or sign up”
customer-support-system-customer-care-station.pages.dev — Контент недоступен. Олицетворение бренда: Facebook; Тип мошенничества: Brand Impersonation. Сводка доказательств: VirusTotal 11/93 (ADMINUSLabs, BitDefender, DNS8, Emsisoft, Fortinet); Google Safe Browsing flagged; PhishDestroy score 88/100. Регистратор: Cloudflare.
Подробный анализ PhishDestroy AI ниже оставлен на английском, чтобы сохранить исходную криминалистическую запись.
Analysis of the domain customer-support-system-customer-care-station.pages.dev indicates a high-risk brand impersonation campaign targeting Facebook users. The domain was registered on March 3, 2026, through Cloudflare, Inc., and currently resolves to IP 157.240.8.35, hosted on AS13335 (Cloudflare, Inc.) in the United States. Nameservers archer.ns.cloudflare.com and meadow.ns.cloudflare.com further confirm Cloudflare as the infrastructure provider. The domain's HTTP status is 403 (Forbidden), though it previously displayed the page title 'Facebook – log in or sign up,' directly aligning with the identified scam type of brand impersonation targeting Facebook.
Detection data reveals the domain appears on at least one security blocklist, with Google Safe Browsing flagging it for social engineering. Eleven of 93 security vendors on VirusTotal have detected the domain as malicious. Trust scores from Scamadviser and Gridinsoft are 1/100 and 0/100, respectively, indicating negligible legitimacy. The SSL certificate is issued by Google Trust Services (WE1), a common feature in both legitimate and malicious Cloudflare-hosted domains.
Infrastructure analysis reveals the use of HTTP/3 and HSTS, technologies often employed to enhance performance and security, which may also serve to evade detection or lend an appearance of legitimacy. The domain was taken offline following identification, though its prior activity and detection metrics suggest a deliberate attempt to deceive users into divulging credentials. Defenders should treat this domain as compromised and block all associated IPs, particularly 157.240.8.35, within network security controls. Monitoring for similar patterns, such as Cloudflare-hosted domains with brand-related subdomains, is recommended to preempt further impersonation attempts.
Процесс реагирования на угрозы
Статус в публичных блок-листах
Криминалистическая аналитика
Технологии · 3 identified
HTTP Strict Transport Security — forces browsers to use HTTPS connections only.
Web infrastructure and security company providing CDN, DDoS mitigation, and DNS services.
www.cloudflare.comThird major version of HTTP protocol, built on QUIC for faster, more reliable connections.
Анализ VirusTotal
Архивные доказательства
Анализ производительности сайта
Google PageSpeed Insights — mobile performance audit of customer-support-system-customer-care-station.pages.dev · checked Apr 11, 2026
Доказательства и внешние отчеты
Повлиял ли на вас этот сайт?
Если вы ввели учетные данные, личную или платежную информацию или загрузили файл с этого домена, примите немедленные меры. Ниже приведены ресурсы, которые помогут вам сообщить об инциденте и защитить себя.
Сообщите об этом в местные органы власти
Выберите свою страну, чтобы получить официальные контакты по киберпреступности или создать проект жалобы →.
Проверить любой домен
Анализ угроз с использованием сохраненного черного списка, WHOIS, DNS и общедоступных доказательств сканирования.
Сканировать сейчасСообщить о фишинге
Добавляйте подозрительные домены в нашу базу данных угроз — защищайте сообщество
СообщитьПоток оперативных данных об угрозах
Недавние сообщения о фишинге и наблюдаемые изменения доступности
ОтслеживатьБудьте в курсе событий, берегите себя
Отслеживайте актуальные угрозы или оспорьте эту запись, если считаете, что это ложное срабатывание