Analysis of the domain facebook-in.blogspot.com on July 28, 2026, confirms it is an active high-risk phishing site targeting user credentials. The domain is flagged by 17 of 91 security vendors on VirusTotal, including detections from PhishDestroy, OpenPhish, and Phishunt, and appears on three security blocklists. Infrastructure analysis reveals the domain resolves to IP address 142.251.14.132, which is associated with Google LLC hosting services, though the domain itself is registered through Google's Blogspot platform.
Nameserver records return NS_NOT_FOUND, indicating potential misconfiguration or deliberate obfuscation of DNS infrastructure. The domain remains active as of the report date, with no evidence of takedown or mitigation. While the exact content of the page has not been analyzed, the domain name and detection context strongly suggest it is designed to mimic Facebook login pages to harvest user credentials.
Defenders should treat this domain as malicious and implement blocking at the DNS, proxy, or endpoint level. Security teams are advised to monitor for connections to 142.251.14.132 and review logs for any interaction with facebook-in.blogspot.com, particularly from users who may have entered credentials. No brand-specific indicators beyond the domain name are confirmed, and the phishing kit or payload remains unclassified.