facebook[.]redirect[.]securelogin[.]ovh
“Facebook - log in or sign up”
facebook.redirect.securelogin.ovh — Неперевірений. Уособлення бренду: Facebook; Тип шахрайства: Social Media Phishing. Зведення доказів: VirusTotal 15/91 (ADMINUSLabs, Criminal IP, BitDefender, CyRadar, ESET); Spamhaus DBL_PHISH; CF Radar malicious; PhishDestroy score 95/100. Реєстратор: OVH.
Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.
The domain facebook.redirect.securelogin.ovh was registered on October 15 2025 through OVH and is currently listed as active. It is classified as a high‑risk brand‑impersonation campaign targeting Facebook, as indicated by the page title “Facebook – log in or sign up”. The site returns an HTTP 308 status, which confirms that it performs a permanent redirect rather than serving content directly.
Infrastructure analysis shows the domain resolves to IP 91.179.180.220, located in Belgium and announced by AS5432 (Proximus NV). No SSL certificate is present, meaning the connection is unencrypted. Authoritative name servers are dns16.ovh.net and ns16.ovh.net, both belonging to the OVH hosting provider. The absence of HTTPS and the use of a 308 redirect are typical of credential‑harvesting infrastructure that forwards victims to a malicious endpoint.
Reputation data indicates a Gridinsoft trust score of 0 / 100 and detection by two public blocklists (PhishDestroy and PhishingDB). VirusTotal reports that 17 out of 95 scanned security vendors flag the domain, reinforcing the high‑risk assessment. The domain appears on two blocklists, confirming that multiple threat‑intel feeds have observed malicious activity associated with this host.
While the current intelligence confirms the domain’s impersonation of Facebook and its active status, the exact payload delivered after the redirect has not been disclosed. Defenders should block the domain at perimeter firewalls and DNS resolvers, monitor outbound connections to 91.179.180.220, and enforce HTTPS‑only policies to prevent accidental credential submission. Continuous telemetry collection from endpoint agents can aid in detecting any subsequent malicious payloads that may be delivered after the redirect.
Сигнали безпеки
Розвіддані з мережевої безпеки
Процес реагування на загрози Pipeline
Статус у публічних блоклистах
Збережений знімок
Аналітика доменів
Технічні деталіDNS, SAN-адреси SSL, мітки часу
ICANN OVERSIGHT
Registration: securelogin.ovh
Акредитація та контекст RAA
Акредитація та контекст RAA
Registrar accreditation and DNS abuse obligations
For the registrable domain securelogin.ovh behind this subdomain, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Аналіз VirusTotal
Архівні докази
Докази та зовнішні звіти
Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога