MALICIOUS — HIGH
facelilt.com için kimlik avı ve güvenlik kontrolü
facelilt[.]
facelilt.com has been identified as an active phishing domain posing as a legitimate cosmetic surgery provider.
- VirusTotal
- 1/94
- Blocklists
- No stored match
- Kullanılabilirlik
- İçerik kullanılamıyor · HTTP 502
Do not enter credentials, seed phrases, payment details, or personal information on this domain.
Jump to section
facelilt.com — İçerik kullanılamıyor (HTTP 502). Marka kimliğine bürünme: Counter-strike; Dolandırıcılık türü: Gaming Scam. Kanıt özeti: VirusTotal 1/94 (Fortinet); PhishDestroy score 56/100. Kayıt kuruluşu: NiceNIC.
Özgün adli kaydı korumak için aşağıdaki ayrıntılı PhishDestroy AI analizi İngilizce bırakılmıştır.
Evidence Analysis
facelilt.com has been identified as an active phishing domain posing as a legitimate cosmetic surgery provider. Current evidence indicates this site is distributing counterfeit Botox treatment offers to unsuspecting internet users. The domain is currently under active investigation following a report from PhishDestroy, a leading fraud prevention platform, which first flagged the domain as suspicious on April 16, 2025. This domain was flagged by 1 of 95 VirusTotal vendors as of the latest scan, indicating that traditional antivirus tools have not yet incorporated detection signatures for this threat. PhishDestroy blocked the domain on April 17, 2025. The site resolves to IP address 104.21.64.71, which is hosted on Cloudflare infrastructure. The domain facelilt.com was registered through NICENIC INTERNATIONAL GROUP CO., LIMITED on April 13, 2025—only three days prior to detection—indicating a very recent and opportunistic registration. The site currently appears on one public blocklist curated by PhishDestroy, underscoring limited but growing recognition as a malicious entity. Despite using a Google Trust Services SSL certificate, the site’s content and registration patterns strongly suggest fraudulent intent rather than legitimate operation. As of today, facelilt.com remains active and accessible to users who have not yet received updated threat intelligence. Given the high risk of financial fraud, identity theft, or exposure to counterfeit medical treatments, users are strongly advised to avoid visiting this domain entirely. If exposure has already occurred, users should scan their devices for malware using reputable antivirus software and monitor financial accounts for unauthorized transactions. Website administrators and cybersecurity teams should implement network-level blocking via DNS or firewall rules targeting the IP 104.21.64.71 and domain facelilt.com. Additionally, organizations are encouraged to update threat intelligence feeds with this domain to prevent future access and propagation. This domain should be treated as a confirmed fraudulent destination pending further investigation by law enforcement or cybersecurity authorities.
Stored source results
Recorded verdicts and infrastructure observations for this domain.
Veri kapsamı12 recorded checks
Ağ Güvenliği İstihbaratı Registrar context
Tehdit Müdahale Pipeline
Genel Engelleme Listesi Durumu
Kaydedilen görüntü
Etki Alanı Analizi
Teknik ayrıntılarDNS, SSL SAN’ları, zaman damgaları
ICANN OVERSIGHT
Akreditasyon ve RAA bağlamı
Akreditasyon ve RAA bağlamı
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Latest Classified Outcome 2026-08-09 03:54:11 UTC
Teknolojiler · 4 identified
Fast CDN for everything on npm — serves raw files from npm packages.
Web infrastructure and security company providing CDN, DDoS mitigation, and DNS services.
www.cloudflare.comThird major version of HTTP protocol, built on QUIC for faster, more reliable connections.
VirusTotal Analizi
Site Performans Analizi
Google PageSpeed Insights — mobile performance audit of facelilt.com · checked Mar 27, 2026
Kanıtlar ve Dış RaporlarIndependent lookups and source reports
PD-20260327-E1E89D Recipient: abuse@nicenic.net, abuse@verisign-grs.com, compliance@icann.org Victim safety and official reportingImmediate actions and verified reporting channels
Hesap kimlik bilgilerini, kişisel bilgileri veya ödeme bilgilerini girdiyseniz ya da bu alan adından bir dosya indirdiyseniz hemen harekete geçin. Aşağıda olayı bildirmenize ve kendinizi korumanıza yardımcı olacak kaynaklar bulunmaktadır.
Yerel Yetkililere Bildirin
resmi siber suç iletişim bilgileri veya şikayet taslağı oluştur → almak için ülkenizi seçin.