lhi0h-uk3o-cic04-2xl-pt5g.pages.dev
Category: Phishing And Fraud
To use full-featured product, you have to purchase a license for Combo Cleaner. Limited seven days free trial available. Combo Cleaner is owned and operated by RCS LT, the parent company of PCRisk.com.
Description of lhi0h-uk3o-cic04-2xl-pt5g.pages.dev
This domain appears to host a page designed to resemble Facebook's login interface. The page title is "Facebook," the screenshot shows Facebook-style branding and a login form, and the listed categories include social media alongside phishing and fraud classifications from multiple web-classification providers.
The domain itself is a random-looking subdomain under pages.dev rather than an official Facebook or Meta-owned web address. Based on the visible content and URL structure, it appears to be a third-party hosted page that may be attempting to collect user credentials by imitating a well-known social media service.
Safety Assessment for lhi0h-uk3o-cic04-2xl-pt5g.pages.dev
Multiple indicators suggest elevated risk at the time of this scan. The domain was flagged by 12 out of 91 security engines, and several classification sources labeled it as phishing or fraud-related. The screenshot also shows a login page closely imitating Facebook while using a non-official pages.dev subdomain, which may indicate an attempt to impersonate the platform and capture account credentials.
The malware scan did not identify malicious files, and several major threat databases were clean at the time of this scan. However, a clean file scan does not outweigh the stronger phishing indicators in this case, especially when the page content appears to mimic a major brand login. In addition, the domain's IP address is listed on one mail-reputation blocklist, which is a weaker signal on its own but still worth noting.
Based on these findings, this website may pose potential risks to visitors.
Technical Description
The site uses a valid SSL/TLS certificate issued by Google Trust Services, with hosting and DNS infrastructure appearing to be provided through Cloudflare. The resolved IP address is 172.66.44.86, geolocated to Canada in the scan data, and the domain uses Cloudflare nameservers. DNSSEC appears to be unsigned.
From a technical standpoint, the presence of HTTPS does not by itself indicate legitimacy, since phishing pages commonly use valid certificates as well. The combination of a random-looking subdomain, Cloudflare-hosted pages.dev deployment, and a Facebook-themed login form on a non-official domain may be consistent with disposable phishing infrastructure.
Share your experience with this website. Was it safe? Did you encounter any issues?