qelvora-gld-zormavi-a5x8dp94.pages.dev
Category: Phishing And Fraud
To use full-featured product, you have to purchase a license for Combo Cleaner. Limited seven days free trial available. Combo Cleaner is owned and operated by RCS LT, the parent company of PCRisk.com.
Description of qelvora-gld-zormavi-a5x8dp94.pages.dev
This domain appears to host a page designed to resemble Facebook's login interface. The page title is "Facebook," and the screenshot shows Meta branding, a login form requesting an email/mobile number and password, and visual elements closely matching the look and layout of Facebook's public sign-in page.
The domain itself is a subdomain on pages.dev, which is a static hosting platform rather than an official Facebook or Meta-owned login domain. Based on the page content, branding, and URL structure, the site appears to be presenting itself as a social media login page rather than an independent service with its own distinct identity.
Because the page uses Facebook branding on an unrelated hosted subdomain, it may be intended to capture account credentials or impersonate a well-known platform. Based on available data, it does not appear to be operated by Meta or Facebook.
Safety Assessment for qelvora-gld-zormavi-a5x8dp94.pages.dev
Multiple security signals indicate elevated risk at the time of this scan. The domain was flagged by 16 out of 91 security engines, and several web-classification providers categorized it as phishing or fraud-related content. In addition, a major threat database listed the URL for social-engineering activity, which is a strong indicator that the page may be attempting to trick visitors into submitting sensitive information.
The screenshot adds further concern because the site closely imitates Facebook's login page while using an unrelated pages.dev subdomain. That resemblance may indicate a look-alike login page intended to collect credentials. Although the malware scan did not detect malicious files and the external-link review did not identify flagged resources, phishing pages often rely on deceptive page design rather than downloadable malware.
There is also a listing on one reputation blocklist associated with link or message abuse, which adds supporting caution, though that signal is secondary compared with the multi-engine phishing detections and social-engineering listing. Based on these findings, this website may pose potential risks to visitors.
Technical Description
The site uses a valid TLS certificate issued by Google Trust Services, with hosting routed through Cloudflare infrastructure at IP address 172.66.44.209. The domain is a pages.dev subdomain and appears to be delivered through a hosted static-site setup rather than a dedicated standalone server. The certificate being valid only indicates encrypted transport and does not by itself verify the legitimacy of the page content.
The domain record shows an age of about five years, though that age applies to the hosted subdomain registration context and should not be treated as proof of trustworthiness for the current page content. DNSSEC appears to be unsigned, and the web server software was not identified in the scan data. The main technical concern is not transport security but the apparent impersonation of a well-known login page on third-party hosting.
Share your experience with this website. Was it safe? Did you encounter any issues?