Analysis conducted on July 29, 2026, identifies facebbook-login.blogspot.com as an active credential phishing domain targeting Facebook users. The domain is registered through Google LLC, leveraging Blogspot infrastructure, and currently resolves to the IP address 142.251.14.132, which is associated with Google's hosting services. Infrastructure review reveals the domain lacks configured nameservers, indicated by the NS_NOT_FOUND status, a common but not definitive indicator of suspicious activity. Detection metrics from VirusTotal show that 10 of 91 security vendors flag the domain as malicious, providing moderate confidence in its classification as a phishing threat.
The domain appears on one security blocklist, specifically PhishDestroy, further corroborating its malicious status. No additional blocklist presence, Safe Browsing flags, or Open Threat Exchange (OTX) pulses were identified in the available data. The domain remains active as of the report date, with no evidence of takedown or mitigation. While the exact content of the phishing page has not been analyzed, the domain name strongly suggests an intent to harvest Facebook login credentials.
Defenders are advised to treat this domain as high-risk and implement blocking measures at the DNS or proxy level. Network security teams should monitor for connections to 142.251.14.132 and the domain itself, particularly in environments where Facebook access is permitted. Given the domain's registration under Google's services, defenders may also consider reporting the abuse to Google's abuse handling channels for potential suspension. No SSL certificate details, autonomous system number (ASN), or hosting country data were available for further infrastructure analysis.