norqula-nqx-zentora-p1t7dw65.pages.dev
Category: Phishing And Fraud
To use full-featured product, you have to purchase a license for Combo Cleaner. Limited seven days free trial available. Combo Cleaner is owned and operated by RCS LT, the parent company of PCRisk.com.
Description of norqula-nqx-zentora-p1t7dw65.pages.dev
This domain appears to host a page designed to resemble Facebook's login interface, including Facebook branding, a login form, and Meta references in the page layout. The page title is "Facebook," and the visible content suggests it is attempting to present itself as a social-media account access or account-recovery page.
The domain itself is a subdomain on pages.dev, which is a static hosting platform rather than an official Facebook-owned domain. Based on the screenshot and metadata, the page does not appear to represent an independent business or informational website; instead, it appears to be a branded login-style page likely intended to collect user credentials or account-related information.
Because the content imitates a major social-media service while being hosted on an unrelated subdomain, the site may be operating as a look-alike page rather than an official service endpoint. Based on available page elements, it does not appear to be operated by the brand shown on the page.
Safety Assessment for norqula-nqx-zentora-p1t7dw65.pages.dev
Multiple security signals indicate elevated risk at the time of this scan. The domain was flagged by 11 out of 91 security engines, with repeated classifications related to phishing and fraud. In addition, multiple web-classification sources categorized the site as phishing/fraud, while the screenshot shows a login page closely imitating Facebook on a non-official pages.dev subdomain. That mismatch between branding and domain is a strong indicator that the page may be a look-alike intended to capture account credentials.
The malware file scan did not detect malicious files at the time of this scan, and several content-focused blacklist databases were clean. However, those cleaner signals are outweighed here by the multi-engine phishing consensus, the visible impersonation of a major platform, and a mail-reputation blocklist listing on the domain's IP address. A generic suspicious listing was also present in one blacklist source, which adds minor supporting concern rather than serving as the main basis for the assessment.
Based on these findings, this website may pose potential risks to visitors.
Technical Description
The site uses a valid SSL/TLS certificate issued by Google Trust Services, with expiry shown as 2026-11-03. It is hosted behind Cloudflare infrastructure on IP address 172.66.44.90, with Cloudflare nameservers and a pages.dev subdomain structure that is commonly used for static-site deployment. DNSSEC appears to be unsigned, which is not uncommon but does mean DNS responses do not benefit from DNSSEC validation.
From a technical standpoint, the most notable concern is not the certificate itself but the combination of hosted login-style content, brand imitation, and reputation-based phishing detections. The server software and exact protocol details were not identified in the scan data.
Share your experience with this website. Was it safe? Did you encounter any issues?