theoldfacebook[.]ddns[.]net
“theoldfacebook.ddns.net”
theoldfacebook.ddns.net — 未验证. 品牌冒充:Facebook; 诈骗类型:Social Media Phishing. 证据摘要: VirusTotal 13/93 (alphaMountain.ai, BitDefender, CyRadar, Forcepoint ThreatSeeker, Fortinet); URLQuery 1 alert; Google Safe Browsing flagged; PhishDestroy score 89/100. 注册商: DynDNS.
为保留原始取证记录,下方的 PhishDestroy AI 详细分析仍使用英文。
This domain was observed by multiple threat‑intelligence feeds as a brand‑impersonation site targeting Facebook users. The fully qualified name theoldfacebook.ddns.net resolves to 87.90.149.239, an address hosted by Bouygues Telecom in France. Registration records show the name was created on 21 February 2026 through DynDNS, a dynamic‑DNS provider commonly abused for fast‑flux and disposable hosting. The site returned HTTP 200 at the time of capture and the page title reported by the crawler was theoldfacebook.ddns.net, offering no legitimate branding cues.
Google Safe Browsing classified the URL under “social engineering”, and the same classification appears on a blocklist managed by PhishDestroy, where the domain is listed as a confirmed phishing entry. VirusTotal analysis indicates that 13 of 93 security vendors submitted a detection for the domain, reinforcing the malicious assessment. Gridinsoft assigned a trust score of 0 / 100, the lowest possible rating. The intelligence tags the activity as “Social Media Phishing”, specifically impersonating Facebook.
The domain is currently reported as taken offline, so live content cannot be examined, and no SSL/TLS details are available. Defenders should continue to block the host and the domain at perimeter and endpoint controls, add the IP address to threat‑intel feeds, and monitor for additional dynamic‑DNS names that resolve to the same ISP or subnet. Ongoing observation of DynDNS registrations related to Facebook‑themed strings is advised, as the infrastructure pattern suggests rapid domain turnover.
网络安全情报
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| Quad9 DNS | theoldfacebook.ddns.net |
malicious | Sinkholed |
威胁响应 Pipeline
公共封禁名单状态
VirusTotal 分析
证据与外部报告
您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。