neh34-u405qr-gpbty6-tde-mrmp.pages.dev
Category: Phishing And Fraud
To use full-featured product, you have to purchase a license for Combo Cleaner. Limited seven days free trial available. Combo Cleaner is owned and operated by RCS LT, the parent company of PCRisk.com.
Description of neh34-u405qr-gpbty6-tde-mrmp.pages.dev
This domain appears to host a page designed to resemble Facebook's login interface. The page title is "Facebook," the screenshot shows Facebook and Meta branding, and the visible content includes a username/password form alongside familiar social-media themed imagery. Based on the page layout and metadata, it appears intended to imitate a social networking login page rather than present an independent service of its own.
The site is hosted on a pages.dev subdomain, which suggests it is being served through a cloud-hosted static site platform rather than from an official Facebook or Meta-owned primary domain. The domain string itself is random-looking and does not appear to match normal branding for a consumer-facing social media service. Based on available data and the page presentation, this appears to be a look-alike login page associated with social media account access.
Safety Assessment for neh34-u405qr-gpbty6-tde-mrmp.pages.dev
Multiple security signals indicate elevated risk at the time of this scan. The domain was flagged by 12 out of 91 security engines, with repeated phishing-related classifications, and multiple web-classification providers categorized it as phishing, fraud, or social media. The screenshot also shows a login page that closely imitates Facebook branding while being hosted on an unrelated pages.dev subdomain, which may indicate an attempt to collect account credentials from visitors who believe they are on the official service.
The malware scan did not detect malicious files in the sampled page resources, but that does not offset the stronger phishing indicators. In addition, the domain's IP address is listed on one mail-reputation blocklist, which is a weaker signal than phishing detections but still worth noting. The combination of a branded login form on a non-official domain, lack of meaningful independent site identity, no traffic ranking, and broad phishing-related detections suggests this website may pose potential risks to visitors.
Based on these findings, this website may pose potential risks to visitors.
Technical Description
The site uses a valid SSL certificate issued by a mainstream certificate authority, with expiry shown as 2026-11-16. It is hosted through Cloudflare infrastructure on IP address 188.114.97.0, with nameservers also pointing to Cloudflare. DNSSEC appears to be unsigned, which is not uncommon but means DNS responses do not appear to have DNSSEC validation protection.
From an infrastructure perspective, the use of HTTPS and a major hosting platform does not by itself establish legitimacy. In this case, the more relevant concern is that a cloud-hosted pages.dev subdomain appears to be presenting a branded Facebook-style login page, which may be inconsistent with expected official deployment patterns for that service.
Share your experience with this website. Was it safe? Did you encounter any issues?