click-to-apply[.]netlify[.]app
“Facebook Page Support Center”
click-to-apply.netlify.app — 未验证. 品牌冒充:Facebook; 诈骗类型:Social Media Phishing. 证据摘要: VirusTotal 14/91 (ADMINUSLabs, alphaMountain.ai, BitDefender, Chong Lua Dao, CyRadar); CF Radar malicious; PhishDestroy score 97/100. 注册商: Netlify.
为保留原始取证记录,下方的 PhishDestroy AI 详细分析仍使用英文。
This domain, click-to-apply.netlify.app, is actively flagged as a high-risk phishing infrastructure targeting Facebook users. Registered on October 24, 2025, through Netlify, the domain resolves to an IP address (63.176.8.218) hosted on Amazon.com, Inc. (AS16509) in Germany. Analysis indicates a 301 HTTP redirect, suggesting the site may forward visitors to additional malicious endpoints. The page title, 'Facebook Page Support Center,' confirms intent to impersonate Facebook’s official support channels, aligning with the reported scam type of social media phishing. Security vendors have detected this domain, with 16 of 95 flagging it as malicious, though the specific payload or phishing kit remains unconfirmed. The domain appears on two blocklists, including PhishDestroy and PhishingDB, and holds a trust score of 0/100 (Gridinsoft) and 1/100 (Scamadviser). SSL certification is provided by DigiCert, a common practice among threat actors to lend superficial legitimacy. Nameservers (dns1.p04.nsone.net, dns2.p04.nsone.net) and detected technologies (Netlify, HSTS) suggest the use of cloud-based hosting to evade traditional takedown efforts. While the exact mechanics of the phishing operation are not yet analyzed, the combination of brand impersonation, active redirects, and security vendor detections warrants immediate blocking. Defenders should treat this domain as a confirmed threat vector for credential harvesting or account takeover attempts targeting Facebook users. Monitoring for associated IPs, subdomains, or newly registered Netlify-hosted domains with similar naming patterns is recommended to preempt further abuse.
安全信号
网络安全情报
威胁响应 Pipeline
公共封禁名单状态
所用技术 · 2 identified
Platform for deploying and hosting modern web applications.
HTTP Strict Transport Security — forces browsers to use HTTPS connections only.
VirusTotal 分析
存档证据
网站性能分析
Google PageSpeed Insights — mobile performance audit of click-to-apply.netlify.app · checked Mar 1, 2026
证据与外部报告
您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。