authfacebook[.]hb[.]gwfaoli[.]com
“Facebook - log in or sign up”
authfacebook.hb.gwfaoli.com — Контент недоступний. Уособлення бренду: Facebook; Тип шахрайства: Social Media Phishing. Зведення доказів: VirusTotal 13 detections (engine total unavailable) (alphaMountain.ai, CRDF, CyRadar, Ermes, Emsisoft); URLQuery 3 alerts; URLScan malicious verdict; Google Safe Browsing flagged; PhishDestroy score 93/100. Реєстратор: IONOS SE.
Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.
On 23 July 2026, the domain authfacebook.hb.gwfaoli.com was observed to be offline but retains indicators of a high‑risk brand‑impersonation campaign targeting Facebook users. The domain was registered on 6 March 2026 through IONOS SE and resolves to the IPv4 address 216.250.125.37, which is hosted in the United States under ASN 8560 (IONOS SE). No TLS certificate is presented, meaning connections are unencrypted. DNS resolution is provided by ns1.fanoermano.info and ns2.fanoermano.info.
The site title returned by HTTP requests is “Facebook - log in or sign up”, matching the declared scam type of Social Media Phishing and the declared impersonated brand, Facebook. Reputation checks show the domain appears on a single security blocklist and is flagged by Google Safe Browsing for social engineering. PhishDestroy has also listed the domain as blocked. VirusTotal analysis reports that 13 of 95 scanned security vendors flagged the domain, indicating a moderate consensus of malicious behavior.
The limited number of detections may reflect the short lifespan of the domain, which was taken offline shortly after creation. Given the combination of brand impersonation, lack of encryption, and multiple independent detections, defenders should add authfacebook.hb.gwfaoli.com to deny‑list rules for DNS and proxy filtering, monitor traffic to the associated IP 216.250.125.37, and consider sinkholing the host to disrupt any residual command‑and‑control activity. Continuous re‑inspection of the IP and its associated name servers is advised, as the infrastructure could be reused for future campaigns. Because the site is currently offline, there is no active payload to retrieve, but the presence of the domain on blocklists and its association with Facebook phishing indicates a high likelihood of credential‑harvesting intent.
Розвіддані з мережевої безпеки
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| Cloudflare DNS | authfacebook.hb.gwfaoli.com |
malicious | Sinkholed |
| OpenDNS | authfacebook.hb.gwfaoli.com |
phishing | Phishing Block |
| DNS4EU | authfacebook.hb.gwfaoli.com |
malicious | Sinkholed |
Процес реагування на загрози Pipeline
Статус у публічних блоклистах
Збережений знімок
Аналітика доменів
Технічні деталіDNS, SAN-адреси SSL, мітки часу
ICANN OVERSIGHT
Registration: gwfaoli.com
Акредитація та контекст RAA
Акредитація та контекст RAA
Registrar accreditation and DNS abuse obligations
For the registrable domain gwfaoli.com behind this subdomain, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Аналіз VirusTotal
Архівні докази
Докази та зовнішні звіти
PD-20260306-57B0DE Recipient: abuse@ionos.com Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога