dravemi-kxt-felquna-c9x3dp76.pages.dev
Category: Phishing
To use full-featured product, you have to purchase a license for Combo Cleaner. Limited seven days free trial available. Combo Cleaner is owned and operated by RCS LT, the parent company of PCRisk.com.
Description of dravemi-kxt-felquna-c9x3dp76.pages.dev
This domain appears to host a page designed to resemble Facebook's login interface. The page title is "Facebook," and the screenshot shows Facebook-style branding, a login form requesting an email/mobile number and password, and Meta branding in the footer. Based on the visible content, the site appears intended to imitate a social media account sign-in page rather than present an independent service of its own.
The domain itself uses a random-looking subdomain on pages.dev, which is a static hosting platform commonly used for legitimate projects but also sometimes abused for temporary or disposable pages. The combination of a non-branded subdomain, social-media-themed content, and a login prompt suggests the page may be attempting to collect account credentials while presenting itself as a familiar platform.
Safety Assessment for dravemi-kxt-felquna-c9x3dp76.pages.dev
Multiple security signals indicate elevated risk at the time of this scan. The domain was flagged by 12 out of 91 security engines, with several classifying it as phishing or fraud-related. Web-classification sources also categorized it as phishing, fraud, or social media, and the screenshot shows a page closely imitating Facebook's login screen on a non-Facebook domain. That kind of mismatch between branding and domain identity is commonly associated with credential-harvesting attempts.
Additional scan context reinforces that concern. The malware scan did not report infected files, but it did attach a generic suspicious label to the domain and several internal links. Blacklist data was mixed: major content-malice checks were clean at the time of this scan, but the domain's IP address was listed on one mail-reputation blocklist, and one additional blacklist source also listed the domain with a generic suspicious classification. Because phishing pages often rely on deceptive page design rather than downloadable malware, a clean file scan does not materially reduce the risk suggested by the broader evidence.
Based on these findings, this website may pose potential risks to visitors.
Technical Description
The site uses a valid SSL/TLS certificate issued by Google Trust Services, expiring in November 2026. It is hosted behind Cloudflare infrastructure on IP address 188.114.97.2, with nameservers adi.ns.cloudflare.com and karl.ns.cloudflare.com. The domain has existed for several years, but it is not ranked in Tranco, which may indicate limited mainstream traffic or a disposable campaign page.
DNSSEC appears to be unsigned, and the web server software was not identified in the scan data. The use of a reputable hosting/CDN provider and valid HTTPS should not be treated as proof of legitimacy, since phishing pages commonly use standard cloud hosting and valid certificates as well.
Share your experience with this website. Was it safe? Did you encounter any issues?