violation-management-a6bc6[.]web[.]app
“Log into Facebook | Facebook”
violation-management-a6bc6.web.app — Контент недоступний. Уособлення бренду: Facebook; Тип шахрайства: Brand Impersonation. Зведення доказів: VirusTotal 15/91 (ADMINUSLabs, alphaMountain.ai, BitDefender, Chong Lua Dao, CyRadar); URLQuery 3 alerts; PhishDestroy score 100/100. Реєстратор: Google Domains.
Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.
PhishDestroy identifies violation-management-a6bc6.web.app as a brand impersonation threat targeting Facebook users. This fraudulent page mimics the authentic Facebook login interface to harvest credentials, posing an elevated risk to visitors who may unknowingly surrender their login details. The domain leverages social engineering tactics by adopting a legitimate-sounding name and mimicking Facebook’s branding to deceive users into entering sensitive information. No drainer kit components were observed in the initial analysis, but the page’s primary function clearly indicates credential theft as its core malicious purpose. This domain resolves to IP address 199.36.158.100 and was registered through Google LLC. It currently holds a VirusTotal detection score of 11/95 security vendors and has been flagged and blocked by the OISD blocklist. The domain features a Google Trust Services SSL certificate, which may lend it an appearance of legitimacy. It has appeared on 1 known security blocklist and uses a subdomain structure typical of Firebase-hosted phishing pages (web.app). The domain’s creation date and full WHOIS history remain under review, but its technical footprint aligns with common phishing infrastructure. As of the latest assessment, violation-management-a6bc6.web.app remains active and accessible, with ongoing attempts to deceive users. Immediate response actions include broad blocklisting by security vendors and domain takedown efforts coordinated through Google Firebase support. Despite these efforts, the domain persists with elevated risk due to its active status and the potential for continued user exposure. Users are strongly advised to avoid this domain entirely, verify URLs before login, and report suspicious pages to Facebook and relevant security teams. Remaining risk is elevated due to active impersonation and moderate detection coverage.
Розвіддані з мережевої безпеки
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| Cloudflare DNS | violation-management-a6bc6.web.app |
malicious | Sinkholed |
| OpenDNS | violation-management-a6bc6.web.app |
phishing | Phishing Block |
| DNS4EU | violation-management-a6bc6.web.app |
malicious | Sinkholed |
Процес реагування на загрози Pipeline
Статус у публічних блоклистах
Аналіз VirusTotal
Архівні докази
Докази та зовнішні звіти
Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога