fbcloned.vercel.app
Category: Phishing
To use full-featured product, you have to purchase a license for Combo Cleaner. Limited seven days free trial available. Combo Cleaner is owned and operated by RCS LT, the parent company of PCRisk.com.
Description of fbcloned.vercel.app
The domain fbcloned.vercel.app appears to host a page designed to imitate Facebook's login interface. The page title, "Facebook Login - Clone," and the screenshot show Facebook branding, a familiar login form, and a "Create new account" button, suggesting the site is presenting itself as a copy of the social media platform's sign-in page rather than as an independent service.
Based on the domain structure, this content is being served from a Vercel-hosted subdomain rather than an official Facebook-owned domain. The use of the word "cloned" in the hostname, combined with the copied branding and layout, indicates the site may have been created to mimic Facebook's authentication page for testing, demonstration, or potentially deceptive credential collection purposes. No evidence in the provided scan data suggests it is operated by Meta or an authorized Facebook service.
Safety Assessment for fbcloned.vercel.app
Multiple security signals indicate elevated risk at the time of this scan. The URL was flagged by 21 out of 91 security engines, and several web-classification sources categorized it as phishing, fraud, or otherwise not recommended. The page content also closely resembles Facebook's login screen while being hosted on an unrelated vercel.app subdomain, which may indicate a look-alike page intended to capture user credentials.
Although the malware scan did not detect malicious files and the listed blacklist databases were clean at the time of this scan, those signals do not outweigh the strong phishing consensus from a large number of security engines and the visible imitation of a well-known brand login page. The very low trust score provided with the scan is also consistent with a high-risk assessment.
Based on these findings, this website may pose potential risks to visitors, particularly anyone asked to enter account credentials or personal information.
Technical Description
The site uses a valid SSL/TLS certificate issued by a mainstream certificate authority, with expiry listed as 2026-07-27. It is hosted on Vercel infrastructure and resolves to IP address 216.198.79.3, with Vercel nameservers configured. DNSSEC appears to be unsigned, which is common but means DNS responses do not benefit from DNSSEC validation.
From a technical scanning perspective, no malicious files, flagged external links, or iframe-based threats were identified in the limited file scan provided. However, the main concern here appears to be social-engineering content rather than exploit delivery: a credential-harvesting page can still operate over valid HTTPS and reputable cloud hosting, so the presence of encryption should not be treated as proof of legitimacy.
Share your experience with this website. Was it safe? Did you encounter any issues?