MALICIOUS — CRITICAL
profile-facebook[.]invoice-ads-program[.]com
PhishDestroy identifies profile-facebook.invoice-ads-program.com as an active high-risk brand-impersonation scam targeting Facebook users.
- VirusTotal
- 21 detections
- Blocklists
- No stored match
- Доступність
- Контент недоступний · HTTP 502
Do not enter credentials, seed phrases, payment details, or personal information on this domain.
Jump to section
profile-facebook.invoice-ads-program.com — Контент недоступний (HTTP 502). Уособлення бренду: Facebook; Тип шахрайства: Brand Impersonation. Зведення доказів: VirusTotal 21 detections (engine total unavailable) (ADMINUSLabs, alphaMountain.ai, BitDefender, Cluster25, CRDF); URLQuery 5 alerts; URLScan malicious verdict; Spamhaus DBL_PHISH; CF Radar malicious; PhishDestroy score 95/100. Реєстратор: Gransy, s.r.o.
Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.
Evidence Analysis
PhishDestroy identifies profile-facebook.invoice-ads-program.com as an active high-risk brand-impersonation scam targeting Facebook users. This domain was flagged by Phishunt, OpenPhish, and PhishingArmy and carries a 22/95 malicious verdict on VirusTotal, confirming its hostile intent.
This site is registered through Gransy, s.r.o. via the .com TLD and was created on April 23, 2026. It resolves to IP address 172.66.0.96 and uses a Google Trust Services SSL certificate to appear legitimate. Despite the certificate, it has been blocked on three independent security blocklists, indicating widespread consensus on its malicious nature. VirusTotal’s aggregated telemetry shows 22 out of 95 participating security vendors classify the domain as malicious, underscoring its elevated threat profile.
To mitigate risk, users must avoid clicking links or entering credentials on this domain. Report the URL to your browser’s phishing alert system and to Facebook’s impersonation reporting page. If you suspect interaction, scan connected devices using up-to-date antivirus software and rotate passwords used on any site accessed after visiting this scam. Parents and educators should warn teens and new users, as brand-impersonation scams often surface on social media ads promising nonexistent bonuses or invoice programs.
Обсяг даних12 recorded checks
Розвіддані з мережевої безпеки
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| DNS4EU | profile-facebook.invoice-ads-program.com |
malicious | Sinkholed |
| OpenDNS | profile-facebook.invoice-ads-program.com |
phishing | Phishing Block |
| DigiCert UltraDNS | profile-facebook.invoice-ads-program.com |
malicious | Sinkholed |
| Hagezi Threat Feed | profile-facebook.invoice-ads-program.com |
malicious | Sinkholed |
| Cloudflare DNS | profile-facebook.invoice-ads-program.com |
malicious | Sinkholed |
Процес реагування на загрози Pipeline
Статус у публічних блоклистах
Збережений знімок
Аналітика доменів
Технічні деталіDNS, SAN-адреси SSL, мітки часу
ICANN OVERSIGHT
Registration: invoice-ads-program.com
Акредитація та контекст RAA
Акредитація та контекст RAA
Registrar accreditation and DNS abuse obligations
For the registrable domain invoice-ads-program.com behind this subdomain, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Технології · 6 identified
Node.js is an open-source, cross-platform, JavaScript runtime environment that executes JavaScript code outside a web browser.
nodejs.org 100% впевненостіReact is an open-source JavaScript library for building user interfaces or UI components.
reactjs.org 100% впевненостіNext.js is a React framework for developing single page Javascript applications.
nextjs.org 100% впевненостіCloudflare is a web-infrastructure and website-security company, providing content-delivery-network services, DDoS mitigation, Internet security, and distributed domain-name-server services.
www.cloudflare.com 100% впевненостіHTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org 100% впевненостіАналіз VirusTotal
Докази та зовнішні звітиIndependent lookups and source reports
PD-20260508-550A69 Recipient: abuse@regtons.com Victim safety and official reportingImmediate actions and verified reporting channels
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.