facebook-photo5[.]blogspot[.]com
“facebook”
facebook-photo5.blogspot.com — 未验证. 品牌冒充:Facebook; 诈骗类型:Brand Impersonation. 证据摘要: VirusTotal 17/91 (Criminal IP, alphaMountain.ai, BitDefender, ESET, Emsisoft); URLScan malicious verdict; 1 external blocklist match (Phishunt); PhishDestroy score 95/100. 注册商: Google Blogger.
为保留原始取证记录,下方的 PhishDestroy AI 详细分析仍使用英文。
This domain, facebook-photo5.blogspot.com, is flagged as a high-risk brand impersonation threat targeting Facebook. Analysis indicates the infrastructure is designed to deceive users into believing they are interacting with legitimate Facebook services, likely to harvest login credentials or distribute malicious payloads. The page title explicitly displays 'facebook,' reinforcing the impersonation attempt, though no specific drainer kit signatures have been confirmed at this time. Infrastructure analysis reveals the domain resolves to the IP address 142.250.154.132, which is associated with legitimate services but repurposed for malicious activity. VirusTotal reports 6 out of 95 security vendors have detected this domain as malicious, indicating moderate but not universal recognition of the threat. The SSL certificate is issued by Google Trust Services, providing a false sense of security to potential victims. No registrar details or domain creation date are publicly available due to the use of a subdomain under blogspot.com, which obscures traditional WHOIS data. Google Safe Browsing (GSB) status and blocklist counts are not explicitly provided, but the domain's active exploitation suggests it may not yet be widely blocked. As of the latest verification, facebook-photo5.blogspot.com remains active and continues to host the impersonation content. Users encountering this domain are advised to avoid interaction, particularly entering credentials or downloading files. Organizations should consider implementing network-level blocks for the domain and its associated IP to mitigate exposure. The remaining risk is classified as high due to the domain's active status, the targeted brand's widespread user base, and the potential for credential theft or malware distribution. Continuous monitoring of related infrastructure is recommended to identify evolving threats linked to this campaign.
威胁响应 Pipeline
公共封禁名单状态
所用技术 · 12 identified
WordPress is a free and open-source content management system written in PHP and paired with a MySQL or MariaDB database. Features include a plugin architecture and a template system.
wordpress.org 置信度 100%Blogger is a blog-publishing service that allows multi-user blogs with time-stamped entries.
www.blogger.com 置信度 100%Java is a class-based, object-oriented programming language that is designed to have as few implementation dependencies as possible.
java.com 置信度 100%YouTube is a video sharing service where users can create their own profile, upload videos, watch, like and comment on other videos.
www.youtube.com 置信度 100%OpenGSE is a test suite used for testing servlet compliance. It is deployed by using WAR files that are deployed on the server engine.
code.google.com 置信度 100%Twitter is a 'microblogging' system that allows you to send and receive short posts called tweets.
twitter.com 置信度 100%AppNexus is a cloud-based software platform that enables and optimizes programmatic online advertising.
appnexus.com 置信度 100%Advertising / conversion-tracking pixel — signals paid marketing activity on this site.
www.advertstream.com 置信度 100%VirusTotal 分析
网站性能分析
Google PageSpeed Insights — mobile performance audit of facebook-photo5.blogspot.com · checked Jul 10, 2026
证据与外部报告
您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。