mrqxb71dran-byktp55lpw-5g7e2d-kp294m.pages.dev
Category: Phishing
To use full-featured product, you have to purchase a license for Combo Cleaner. Limited seven days free trial available. Combo Cleaner is owned and operated by RCS LT, the parent company of PCRisk.com.
Description of mrqxb71dran-byktp55lpw-5g7e2d-kp294m.pages.dev
This domain appears to be a page hosted on the pages.dev platform rather than an official standalone Facebook or Meta-owned domain. Based on the page title, screenshot, and visible interface elements, it presents itself as a Facebook login page and includes branding associated with Facebook and Meta.
The content shown is consistent with a social-media account sign-in portal, including fields for email or mobile number and password, along with links such as "Forgot password?" and "Create new account." However, the domain name itself is an unrelated randomized subdomain on a hosting platform, which may indicate that the page is imitating a well-known service rather than being operated by that service's official owner.
Safety Assessment for mrqxb71dran-byktp55lpw-5g7e2d-kp294m.pages.dev
Multiple security signals indicate elevated risk at the time of this scan. The domain was flagged by 13 out of 91 security engines, with several classifying it as phishing or fraud-related, and multiple web-classification providers also categorized it as phishing. The screenshot further shows a login page styled to resemble Facebook, while the actual domain is a pages.dev subdomain rather than an official Facebook-controlled domain, which may indicate an attempt to collect account credentials through imitation.
Additional scan context is mixed but still concerning overall. A malware scan did not report confirmed malicious files, although it did attach a generic suspicious heuristic to the domain and several internal URLs. Blacklist data also shows the domain's IP address listed on one mail-reputation blocklist, which is a weaker signal than direct phishing detections but still worth noting. The combination of multi-engine phishing detections, impersonation-style presentation, and credential-entry functionality materially increases risk.
Based on these findings, this website may pose potential risks to visitors, particularly anyone asked to enter login credentials.
Technical Description
The site uses a valid SSL/TLS certificate issued by a mainstream certificate authority, with expiry listed in November 2026. It is hosted behind Cloudflare infrastructure on IP address 172.66.47.135, with Cloudflare nameservers and a pages.dev hosting pattern that suggests deployment on a static hosting platform. The domain is approximately five years old, although that age may reflect the hosted subdomain record rather than trustworthiness of the page content itself.
DNSSEC appears to be unsigned, and the web server software was not identified in the scan data. From a security perspective, the main concern is not the TLS setup but the apparent mismatch between the branded login experience and the unrelated hosting-domain identity, along with phishing-related detections from multiple security engines.
Share your experience with this website. Was it safe? Did you encounter any issues?