invoice-partner-meta-for-business[.]surge[.]sh
“Meta Privacy Center - Community Standards & Policies”
invoice-partner-meta-for-business.surge.sh — Контент недоступний. Уособлення бренду: Facebook. Зведення доказів: VirusTotal 14/95 (ADMINUSLabs, alphaMountain.ai, BitDefender, CyRadar, ESET); URLScan malicious verdict; CF Radar malicious; PhishDestroy score 92/100. Реєстратор: Surge.sh.
Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.
invoice-partner-meta-for-business.surge.sh was flagged by multiple security vendors as a phishing infrastructure targeting Meta users. The only publicly observed attribute is the HTML title "Meta Privacy Center - Community Standards & Policies", suggesting an attempt to masquerade as an official Meta privacy portal. The domain is registered through the Surge.sh service and delegated to the authoritative name servers ns1.surge.sh and ns2.surge.sh. DNS resolution points to 188.166.132.94, an address owned by DigitalOcean, LLC (AS14061) and geolocated to the Netherlands.
HTTPS connections present a Sectigo Limited RSA Domain Validation Secure Server CA certificate, a standard DV certificate that supplies encryption but no brand assurance. HTTP requests return a 404 status code, and the site has been taken offline, which prevents direct content analysis. VirusTotal records indicate that 14 of 95 scanned security vendors flagged the domain, reinforcing suspicion of malicious intent. The domain is listed on at least one external blocklist and is actively blocked by PhishDestroy, confirming that threat‑intelligence feeds recognize it as a phishing vector.
Current evidence is limited to infrastructure data and the observed page title; the actual landing page content, payloads, or user‑interaction mechanisms remain unknown due to the offline status. Defenders should immediately block the domain and its hosting IP, incorporate the host into network‑level deny lists, and monitor for any resurgence of the domain or related Surge.sh sub‑domains. Adding the IP address to sinkhole or threat‑intel platforms can aid in early detection of re‑use. Continuous observation of the AS14061 range is advised, as the host may be repurposed for future phishing campaigns.
Розвіддані з мережевої безпеки
Процес реагування на загрози Pipeline
Статус у публічних блоклистах
Аналіз VirusTotal
Архівні докази
Докази та зовнішні звіти
Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога