MALICIOUS — CRITICAL
facebook-notification[.]blogspot[.]com
PhishDestroy initiated a brand-impersonation probe on facebook-notification.blogspot.com after automated feeds flagged it for mimicking Facebook’s notification system.
- VirusTotal
- 18/91
- Blocklists
- 1 · Phishunt
- 可用性
- 最后已知的活跃状态 · HTTP 200
Do not enter credentials, seed phrases, payment details, or personal information on this domain.
Jump to section
facebook-notification.blogspot.com — 最后已知的活跃状态 (HTTP 200). 品牌冒充:Facebook; 诈骗类型:Brand Impersonation. 证据摘要: VirusTotal 18/91 (ADMINUSLabs, Criminal IP, alphaMountain.ai, BitDefender, Chong Lua Dao); URLQuery 3 alerts; 1 external blocklist match (Phishunt); CF Radar malicious; PhishDestroy score 100/100. 注册商: Google Blogger.
为保留原始取证记录,下方的 PhishDestroy AI 详细分析仍使用英文。
Evidence Analysis
PhishDestroy initiated a brand-impersonation probe on facebook-notification.blogspot.com after automated feeds flagged it for mimicking Facebook’s notification system. The domain uses a Blogspot subdomain to lend superficial legitimacy and targets users expecting official Facebook alerts. No drainer kit payloads were retrieved at time of inspection, but the impersonation style suggests credential-harvesting or session-token theft once victims interact with embedded links or buttons.
This domain was flagged under seed 95f831 and resolves to IP 142.251.127.132. VirusTotal currently records 0 detections out of 95 engines; the SSL certificate is issued by Google Trust Services, indicating HTTPS is enabled but not a guarantee of safety. Creation date and registrar details remain unverified in public WHOIS at this stage; Google Safe Browsing has not yet blacklisted the page.
The domain is presently ACTIVE and under continuous monitoring. PhishDestroy recommends users refrain from clicking any links or entering credentials on this page. Block rules should be added at the network perimeter for IP 142.251.127.132 and the exact domain string. Risk remains low-to-moderate until automated analysis confirms absence of malicious JavaScript or phishing-kit components.
数据覆盖范围13 recorded checks
网络安全情报
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| DNS4EU | facebook-notification.blogspot.com |
malicious | Sinkholed |
| Cloudflare DNS | facebook-notification.blogspot.com |
malicious | Sinkholed |
| OpenDNS | facebook-notification.blogspot.com |
phishing | Phishing Block |
威胁响应 Pipeline
公共封禁名单状态
所用技术 · 6 identified
Blogger is a blog-publishing service that allows multi-user blogs with time-stamped entries.
www.blogger.com 置信度 100%Java is a class-based, object-oriented programming language that is designed to have as few implementation dependencies as possible.
java.com 置信度 100%OpenGSE is a test suite used for testing servlet compliance. It is deployed by using WAR files that are deployed on the server engine.
code.google.com 置信度 100%Google AdSense is a program run by Google through which website publishers serve advertisements that are targeted to the site content and audience.
www.google.com 置信度 100%HTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org 置信度 100%VirusTotal 分析
网站性能分析
Google PageSpeed Insights — mobile performance audit of facebook-notification.blogspot.com · checked Apr 27, 2026
网站配置分析
证据与外部报告Independent lookups and source reports
Victim safety and official reportingImmediate actions and verified reporting channels
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。