cnivok-krelna-mk3006tgb-bjbyh-2ch378.pages.dev
Category: Phishing
To use full-featured product, you have to purchase a license for Combo Cleaner. Limited seven days free trial available. Combo Cleaner is owned and operated by RCS LT, the parent company of PCRisk.com.
Description of cnivok-krelna-mk3006tgb-bjbyh-2ch378.pages.dev
This domain appears to host a page designed to resemble Facebook's login interface, including Facebook branding, a Meta footer, and a sign-in form requesting an email/mobile number and password. The page title is "Facebook," and the visible layout closely mirrors a social-media account login portal rather than an independent website with its own brand identity.
Based on the domain structure, this is a subdomain on pages.dev, a hosting platform commonly used for static web deployments. The hostname itself is a long, random-looking string and does not appear to match Facebook's official domain naming. That combination suggests the page may be an unofficial hosted copy intended to imitate a well-known social platform rather than a legitimate Facebook-operated property.
Safety Assessment for cnivok-krelna-mk3006tgb-bjbyh-2ch378.pages.dev
Several security signals indicate elevated risk at the time of this scan. The URL was flagged as phishing by 5 out of 91 security engines, and the page content visibly imitates Facebook's login screen while being served from an unrelated pages.dev subdomain. That mismatch between the displayed brand and the actual domain is a strong warning sign that the site may be attempting to collect account credentials from visitors.
Other scan results were mixed. A malware scan did not detect malicious files, and major content-focused threat databases listed in the scan were clean at the time of review. However, the domain's IP address was listed on one mail-reputation blocklist, which is a weaker signal than direct phishing detections but still worth noting. In this case, the phishing-style presentation and multi-engine detections carry more weight than the clean file scan.
Based on these findings, this website may pose potential risks to visitors.
Technical Description
The site uses a valid SSL/TLS certificate issued by a mainstream certificate provider, with expiry shown as 2026-09-29. It is hosted through Cloudflare infrastructure on IP address 188.114.96.0, with nameservers also delegated to Cloudflare. DNSSEC appears to be unsigned based on the provided WHOIS data.
From a technical standpoint, the use of HTTPS does not by itself indicate legitimacy; phishing pages commonly use valid certificates as well. The hosting setup appears consistent with a static site deployment on pages.dev, and the random-looking subdomain, combined with a login form imitating a major platform, may be a technical indicator of disposable or campaign-style infrastructure.
Share your experience with this website. Was it safe? Did you encounter any issues?