pwn1i-7mx-e83-7be-za3yks.pages.dev
Category: Phishing
To use full-featured product, you have to purchase a license for Combo Cleaner. Limited seven days free trial available. Combo Cleaner is owned and operated by RCS LT, the parent company of PCRisk.com.
Description of pwn1i-7mx-e83-7be-za3yks.pages.dev
This domain appears to host a page designed to resemble Facebook's login interface. The page title is "Facebook," the screenshot shows Facebook and Meta branding, and the visible content includes email/phone and password fields along with a login button and account-creation links. The URL structure also references an "appeal" workflow, which may indicate an attempt to collect credentials under the pretext of account recovery or review.
The site is hosted on a pages.dev subdomain, which is a static hosting platform commonly used for legitimate projects but also sometimes used for temporary or disposable pages. Based on the branding shown and the mismatch between the hosted subdomain and the service being depicted, this page appears to be presenting itself as a Facebook-related login or account-action page rather than an independent website operated under its own brand.
Safety Assessment for pwn1i-7mx-e83-7be-za3yks.pages.dev
Several security signals indicate elevated risk at the time of this scan. The domain was flagged by 7 out of 91 security engines, with the detections broadly classifying it as phishing. In addition, the page visually imitates Facebook's sign-in experience while being hosted on an unrelated pages.dev subdomain, which may be consistent with credential-harvesting behavior. Although one malware scan reported no flagged files, that result does not outweigh multiple phishing-oriented detections and the strong visual impersonation pattern.
Blacklist and reputation data were mixed rather than fully clean. Major content-malice databases in the provided scan did not report a listing, but the domain's IP address was listed on one mail-reputation blocklist, and one additional blacklist entry marked it with a generic malicious-object label. Those secondary signals are less conclusive on their own, but they add caution when viewed alongside the phishing detections and the login-page impersonation.
Based on these findings, this website may pose potential risks to visitors.
Technical Description
The site uses a valid TLS certificate issued by Google Trust Services, with certificate expiry listed as 2026-09-29. It is hosted behind Cloudflare infrastructure on IP address 172.66.47.101, with Cloudflare nameservers and a pages.dev subdomain. DNSSEC appears to be unsigned, which is not uncommon but means DNS responses do not benefit from DNSSEC validation.
From a security perspective, the main concern is not the TLS setup but the apparent mismatch between the domain and the branded content shown on the page. The use of a hosted subdomain, generic static assets, and a login form imitating a major platform may be consistent with a phishing setup at the time of this scan.
Share your experience with this website. Was it safe? Did you encounter any issues?