dravixa-gld-belquna-r9t8fw26.pages.dev
Category: Phishing
To use full-featured product, you have to purchase a license for Combo Cleaner. Limited seven days free trial available. Combo Cleaner is owned and operated by RCS LT, the parent company of PCRisk.com.
Description of dravixa-gld-belquna-r9t8fw26.pages.dev
This domain appears to host a page designed to resemble Facebook's login interface, including Facebook branding, a Meta footer, and a sign-in form requesting an email/mobile number and password. The page title is "Facebook," and the visible layout closely mirrors a social-media account access page rather than an independent website with its own brand identity.
The site is served from a pages.dev subdomain, which suggests it may be deployed through a cloud-hosted static site platform rather than operated on Facebook's official domain infrastructure. Based on the domain name, page content, and screenshot, it does not appear to represent an official Facebook or Meta-owned login endpoint.
Safety Assessment for dravixa-gld-belquna-r9t8fw26.pages.dev
Multiple security signals indicate elevated risk at the time of this scan. The domain was flagged by 11 out of 91 security engines, with the detections broadly classifying it as phishing. In addition, the page visually imitates Facebook's login screen while using an unrelated pages.dev subdomain, which may indicate an attempt to collect account credentials by resembling a well-known service. Although the malware scan did not identify malicious files and several content-focused blacklist databases were clean at the time of review, those results do not outweigh the phishing-related detections and the strong visual impersonation pattern.
There is also a secondary reputation concern: the domain's IP address is listed on one mail-reputation blocklist. That signal alone would be weak evidence, but in this case it appears alongside multi-engine phishing detections and a login page that may mislead visitors into believing they are interacting with Facebook.
Based on these findings, this website may pose potential risks to visitors.
Technical Description
The site uses a valid SSL/TLS certificate issued by a mainstream certificate authority, with expiry shown as 2026-10-19. It is hosted behind Cloudflare infrastructure on IP address 188.114.96.2, with Cloudflare nameservers and a registrar record through CloudFlare, Inc. DNSSEC appears to be unsigned.
From a technical standpoint, the presence of HTTPS does not by itself establish legitimacy, since phishing pages commonly use valid certificates as well. The use of a cloud-hosted pages.dev subdomain, combined with branding that appears to imitate a major platform's login page, may be a notable concern at the time of this scan.
Share your experience with this website. Was it safe? Did you encounter any issues?