mantle-portal-1761510377531-jkmki4dx.pages[.]dev
Category: Phishing
To use full-featured product, you have to purchase a license for Combo Cleaner. Limited seven days free trial available. Combo Cleaner is owned and operated by RCS LT, the parent company of PCRisk.com.
Description of mantle-portal-1761510377531-jkmki4dx.pages[.]dev
This domain is hosted on a pages.dev subdomain, which is commonly used for static site hosting and temporary project deployments. Based on the page title and screenshot, the site appears to present itself as a Facebook login page, including branding elements associated with Meta and a sign-in form requesting an email or mobile number and password.
The domain name itself does not appear to be an official Facebook or Meta web address. Instead, it looks like an automatically generated deployment name on a hosting platform. That combination suggests this page may be a hosted imitation of a social media login portal rather than an official service endpoint operated by the brand it references.
Because the visible content is centered on account login and uses recognizable Facebook branding on an unrelated host, the site appears to be aimed at collecting user credentials or mimicking a legitimate authentication page. Based on available data, it does not appear to represent a standalone business, publisher, or normal informational website.
Safety Assessment for mantle-portal-1761510377531-jkmki4dx.pages[.]dev
Scan results show mixed but concerning signals at the time of this scan. Two out of 91 security engines flagged the domain for phishing, while other malware and blacklist checks did not detect threats. Although a low detection count can sometimes reflect limited visibility, the page content itself materially increases concern because it appears to imitate Facebook on a non-official domain.
The strongest risk indicator here is the mismatch between the branding shown on the page and the actual hosted address. A login form asking for Facebook credentials on a pages.dev subdomain may be consistent with credential-harvesting behavior. The absence of flagged files or external links in the scan does not remove that concern, since phishing pages can be technically simple and still pose risk.
Based on the screenshot, domain context, and the limited phishing detections from security engines, this website may pose potential risks to visitors at the time of this scan.
Technical Description
The site uses a valid SSL/TLS certificate issued through a mainstream certificate provider, and it is served behind Cloudflare infrastructure from an IP associated with Cloudflare. The certificate validity indicates encrypted transport, but HTTPS alone does not verify that the page is legitimate or affiliated with the brand it displays. DNSSEC appears to be unsigned.
The domain has existed for several years, but this is a hosted subdomain rather than a long-established standalone brand domain. It is not ranked in major popularity datasets, and the use of a generic hosting subdomain for a branded login page is a notable concern. No malicious files, external links, or iframes were identified in the provided scan data at the time of analysis.
Share your experience with this website. Was it safe? Did you encounter any issues?