MALICIOUS — CRITICAL
facebook-setting[.]invoice-ads-process[.]com
This domain, facebook-setting.invoice-ads-process.com, is flagged for brand impersonation targeting Facebook users through a credential harvesting scheme.
- VirusTotal
- 21/91
- Blocklists
- No stored match
- Kullanılabilirlik
- İçerik kullanılamıyor · HTTP 502
Do not enter credentials, seed phrases, payment details, or personal information on this domain.
Jump to section
facebook-setting.invoice-ads-process.com — İçerik kullanılamıyor (HTTP 502). Marka kimliğine bürünme: Facebook; Dolandırıcılık türü: Brand Impersonation. Kanıt özeti: VirusTotal 21/91 (ADMINUSLabs, Criminal IP, alphaMountain.ai, BitDefender, Chong Lua Dao); URLQuery 6 alerts; URLScan malicious verdict; Spamhaus DBL_PHISH; CF Radar malicious; PhishDestroy score 95/100. Kayıt kuruluşu: Gransy, s.r.o.
Özgün adli kaydı korumak için aşağıdaki ayrıntılı PhishDestroy AI analizi İngilizce bırakılmıştır.
Evidence Analysis
facebook-setting.invoice-ads-process.com — Facebook Credential
facebook-setting.invoice-ads-process.com impersonates Facebook Accounts Centre to steal credentials. Detected by 21/95 security vendors, this active phishing.
This domain, facebook-setting.invoice-ads-process.com, is flagged for brand impersonation targeting Facebook users through a credential harvesting scheme. The phishing page displays an 'Accounts Centre' title, mimicking Facebook's authentication interface to deceive victims into submitting login credentials. Analysis indicates the site employs modern web technologies, including Node.js, React, and Next.js, alongside Cloudflare hosting, suggesting an attempt to evade detection through legitimate-looking infrastructure. Technical indicators confirm elevated risk: the domain was registered on May 3, 2026, through Gransy, s.r.o., and resolves to IP address 162.159.140.98. VirusTotal reports 21 out of 95 security vendors detecting malicious activity, while Gridinsoft assigns a trust score of 0/100. The domain appears on one security blocklist and is currently blocked by at least one anti-phishing system. No Google Safe Browsing (GSB) flags are recorded at this time, though this may reflect a lag in detection rather than absence of threat. The domain remains active, posing an ongoing risk to users who may encounter it through phishing emails, ads, or social engineering tactics. Response actions should include immediate blocking of the domain and IP at network and endpoint levels, alongside monitoring for related infrastructure (e.g., subdomains, newly registered lookalike domains). Users are advised to verify URLs before entering credentials, enable multi-factor authentication on Facebook accounts, and report suspicious links to their security teams. Despite current blocking efforts, the domain's use of Cloudflare and modern web frameworks may prolong its operational lifespan, warranting continued vigilance.
Stored source results
Recorded verdicts and infrastructure observations for this domain.
Veri kapsamı12 recorded checks
Ağ Güvenliği İstihbaratı
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| Cloudflare DNS | facebook-setting.invoice-ads-process.com |
malicious | Sinkholed |
| OpenDNS | facebook-setting.invoice-ads-process.com |
phishing | Phishing Block |
| DigiCert UltraDNS | facebook-setting.invoice-ads-process.com |
malicious | Sinkholed |
| Hagezi Threat Feed | facebook-setting.invoice-ads-process.com |
malicious | Sinkholed |
| DNS4EU | facebook-setting.invoice-ads-process.com |
malicious | Sinkholed |
| Quad9 DNS | facebook-setting.invoice-ads-process.com |
malicious | Sinkholed |
Tehdit Müdahale Pipeline
Genel Engelleme Listesi Durumu
Kaydedilen görüntü
Etki Alanı Analizi
Teknik ayrıntılarDNS, SSL SAN’ları, zaman damgaları
ICANN OVERSIGHT
Registration: invoice-ads-process.com
Akreditasyon ve RAA bağlamı
Akreditasyon ve RAA bağlamı
Registrar accreditation and DNS abuse obligations
For the registrable domain invoice-ads-process.com behind this subdomain, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Teknolojiler · 6 identified
Node.js is an open-source, cross-platform, JavaScript runtime environment that executes JavaScript code outside a web browser.
nodejs.org %100 güvenReact is an open-source JavaScript library for building user interfaces or UI components.
reactjs.org %100 güvenNext.js is a React framework for developing single page Javascript applications.
nextjs.org %100 güvenCloudflare is a web-infrastructure and website-security company, providing content-delivery-network services, DDoS mitigation, Internet security, and distributed domain-name-server services.
www.cloudflare.com %100 güvenHTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org %100 güvenVirusTotal Analizi
Site Performans Analizi
Google PageSpeed Insights — mobile performance audit of facebook-setting.invoice-ads-process.com · checked Jun 26, 2026
Kanıtlar ve Dış RaporlarIndependent lookups and source reports
PD-20260507-034B0E Recipient: abuse@regtons.com Victim safety and official reportingImmediate actions and verified reporting channels
Hesap kimlik bilgilerini, kişisel bilgileri veya ödeme bilgilerini girdiyseniz ya da bu alan adından bir dosya indirdiyseniz hemen harekete geçin. Aşağıda olayı bildirmenize ve kendinizi korumanıza yardımcı olacak kaynaklar bulunmaktadır.
Yerel Yetkililere Bildirin
resmi siber suç iletişim bilgileri veya şikayet taslağı oluştur → almak için ülkenizi seçin.