facebook-2-0-dun.vercel.app
Category: Phishing
To use full-featured product, you have to purchase a license for Combo Cleaner. Limited seven days free trial available. Combo Cleaner is owned and operated by RCS LT, the parent company of PCRisk.com.
Description of facebook-2-0-dun.vercel.app
This domain appears to host a login-themed webpage presented as a Facebook sign-in screen. The screenshot shows Facebook branding, a short promotional tagline, and buttons labeled for logging in with Facebook or Google, suggesting the page is intended to collect account credentials or redirect users through a social-login flow rather than provide independent content or services.
Based on the domain structure, this page is hosted as a subdomain on Vercel rather than on an official Facebook-owned domain. The naming pattern includes the word "facebook" combined with extra characters, which may indicate an unofficial page attempting to resemble a well-known social media service. No clear operator identity, company details, or legitimate site metadata are visible from the scan data provided.
Safety Assessment for facebook-2-0-dun.vercel.app
Multiple security signals indicate elevated risk at the time of this scan. The domain was flagged by 18 out of 91 security engines, and several web-classification sources categorized it as phishing or fraud-related. In addition, the page visually imitates Facebook's login interface while being served from a third-party hosting subdomain, which may be consistent with credential-harvesting or brand impersonation behavior.
The malware scan summary itself reported no flagged files, but it also applied a generic malicious-object label to the domain and many linked static assets. Blacklist results were mixed: major content-malice databases in the provided data were largely clean, but one threat database listed the domain and the server IP was listed on one mail-reputation blocklist. That DNS-based listing is a weaker signal on its own, but in this case it appears alongside substantial multi-engine phishing detections and a deceptive-looking login page.
Taken together, the domain appears to resemble Facebook without being an official Facebook property, and the overall evidence may indicate a phishing setup. Based on these findings, this website may pose potential risks to visitors.
Technical Description
The site is hosted on Vercel infrastructure and resolves to IP address 216.198.79.195 in Walnut, United States. It uses a valid SSL/TLS certificate issued by Google Trust Services with an expiry date of 2026-09-26, which means the connection can be encrypted in transit; however, valid HTTPS alone does not verify that the site is legitimate. DNSSEC appears to be unsigned, so there is no additional DNS integrity protection indicated in the scan data.
The page appears to be built with a modern JavaScript framework, likely Next.js, based on the referenced /_next/static assets. While the hosting platform and certificate are standard, the main technical concern is not server misconfiguration but the apparent use of a hosted subdomain to present a login page resembling a major brand. That pattern may be associated with phishing campaigns, especially when combined with broad security-engine detections.
Share your experience with this website. Was it safe? Did you encounter any issues?