facebook-downloader[.]czhyk[.]biz[.]id
“Verify to Continue”
facebook-downloader.czhyk.biz.id — Doğrulanmamış. Marka kimliğine bürünme: Facebook; Dolandırıcılık türü: Brand Impersonation. Kanıt özeti: VirusTotal 13/91 (ADMINUSLabs, alphaMountain.ai, BitDefender, ESET, Forcepoint ThreatSeeker); PhishDestroy score 89/100. Kayıt kuruluşu: PT JC Indonesia.
Özgün adli kaydı korumak için aşağıdaki ayrıntılı PhishDestroy AI analizi İngilizce bırakılmıştır.
Domain facebook-downloader.czhyk.biz.id is currently under active investigation for engaging in brand impersonation, specifically targeting Facebook users with a counterfeit downloader service. The site is confirmed active and operates under the guise of providing legitimate Facebook content extraction tools, luring victims into entering credentials or downloading malicious payloads. This deception is a direct attempt to exploit user trust in the Facebook brand for credential harvesting or malware distribution.
This domain was flagged by 18 of 95 VirusTotal vendors at the time of analysis, indicating it has evaded immediate detection by most antivirus engines. The domain resolves to IP address 15.235.206.12 and is secured with a Let's Encrypt SSL certificate, which may enhance its perceived legitimacy. The seed identifier 6f3a78 correlates this domain to a broader campaign of brand impersonation scams, though detailed registrar or blocklist data remains unavailable. The lack of detections suggests this threat is either newly deployed or employs sophisticated evasion techniques to bypass initial security scans.
Current status indicates this threat is active and evolving, with potential for escalation if undetected. Users are strongly advised to avoid interacting with this domain or any linked pages, particularly those requesting login credentials or downloads. Conduct a VirusTotal scan of the domain (18/95 detections as of analysis) to verify its status, and report the domain to relevant cybersecurity authorities or blocklist maintainers. Organizations should update firewall rules to block IP 15.235.206.12 and monitor network traffic for connections to this domain or its subdomains. Exercise heightened caution with domains offering free services tied to high-value brands like Facebook, as these are frequent vectors for credential theft and malware delivery.
Ağ Güvenliği İstihbaratı
Tehdit Müdahale Pipeline
Genel Engelleme Listesi Durumu
Teknolojiler · 6 identified
Server-side scripting language designed for web development.
High-performance web server compatible with Apache configurations.
Web infrastructure and security company providing CDN, DDoS mitigation, and DNS services.
www.cloudflare.comIcon font library.
Third major version of HTTP protocol, built on QUIC for faster, more reliable connections.
VirusTotal Analizi
Arşivlenmiş Kanıtlar
Site Performans Analizi
Google PageSpeed Insights — mobile performance audit of facebook-downloader.czhyk.biz.id · checked Apr 1, 2026
Kanıtlar ve Dış Raporlar
Bu Siteden Etkilendiniz mi?
Hesap kimlik bilgilerini, kişisel bilgileri veya ödeme bilgilerini girdiyseniz ya da bu alan adından bir dosya indirdiyseniz hemen harekete geçin. Aşağıda olayı bildirmenize ve kendinizi korumanıza yardımcı olacak kaynaklar bulunmaktadır.
Yerel Yetkililere Bildirin
resmi siber suç iletişim bilgileri veya şikayet taslağı oluştur → almak için ülkenizi seçin.
Herhangi Bir Alan Adını Kontrol Et
Saklanan engelleme listesi, WHOIS, DNS ve genel tarama kanıtlarını kullanarak tehdit analizi
Şimdi TaraOltalama Olayını Bildir
Şüpheli alan adlarını tehdit veritabanımıza bildirin — topluluğu koruyun
BildirCanlı Tehdit Akışı
Son kimlik avı raporları ve gözlemlenen kullanılabilirlik değişiklikleri
İzleGelişmelerden Haberdar Olun, Güvende Kalın
Canlı tehditleri izleyin veya bunun yanlış bir uyarı olduğunu düşünüyorsanız bu kayda itiraz edin