7ro-wwv-ftvh-2np810-9v8crh.pages.dev
Category: Phishing
To use full-featured product, you have to purchase a license for Combo Cleaner. Limited seven days free trial available. Combo Cleaner is owned and operated by RCS LT, the parent company of PCRisk.com.
Description of 7ro-wwv-ftvh-2np810-9v8crh.pages.dev
This domain appears to host a page designed to resemble Facebook's login interface. The page title is "Facebook," the screenshot shows Facebook and Meta branding, and the visible layout imitates a social-media account sign-in page with fields for email/mobile number and password.
Based on the domain structure, this is not an official Facebook or Meta web address. It is hosted on a pages.dev subdomain, which is commonly used for static site hosting, and the available content suggests the page may be intended to collect login credentials or direct users through an account-related workflow such as an appeal or sign-in process.
The site does not appear to represent an independent business, publisher, or service with its own clear identity. Instead, the branding and page presentation indicate that it may be presenting itself as a Facebook-related login page while operating from an unrelated hosted subdomain.
Safety Assessment for 7ro-wwv-ftvh-2np810-9v8crh.pages.dev
Multiple security signals indicate elevated risk at the time of this scan. The domain was flagged by 16 out of 91 security engines, and several web-classification sources categorized it as phishing or fraud-related. In addition, the screenshot shows a login page closely imitating Facebook while using a non-official domain, which is a common sign of credential-harvesting activity.
The malware scan did not detect malicious files, but that does not materially reduce the concern here because phishing pages often rely on simple web forms rather than downloadable malware. Blacklist data was mixed: major content-malice databases shown in the scan were largely clean, but one generic suspicious listing was present and the domain's IP address was also listed on one mail-reputation blocklist. That mail-reputation signal is weaker than direct phishing detections, but it still adds a minor cautionary note.
Taken together, the strongest indicators are the multi-engine phishing detections, the phishing-related categorization, and the page's apparent imitation of Facebook branding on an unrelated subdomain. Based on these findings, this website may pose potential risks to visitors.
Technical Description
The site is hosted behind Cloudflare infrastructure on IP address 172.66.46.248 and uses a valid TLS certificate issued by Google Trust Services, with expiry shown as 2026-11-07. The domain is a pages.dev subdomain, suggesting deployment through a static hosting platform rather than a dedicated standalone server. DNSSEC appears to be unsigned.
From a security perspective, the presence of HTTPS should not be treated as proof of legitimacy, since phishing pages commonly use valid certificates as well. The domain has existed for several years, but the key concern is the apparent use of a hosted subdomain to present a branded login page unrelated to the official service domain.
Share your experience with this website. Was it safe? Did you encounter any issues?