sp11ct-ralvek-biz8-kormel-dasvik.pages.dev
Category: Phishing
To use full-featured product, you have to purchase a license for Combo Cleaner. Limited seven days free trial available. Combo Cleaner is owned and operated by RCS LT, the parent company of PCRisk.com.
Description of sp11ct-ralvek-biz8-kormel-dasvik.pages.dev
This domain appears to host a page designed to resemble Facebook's login interface, including Facebook branding, Meta references, and a sign-in form requesting an email/mobile number and password. The page title is "Facebook," and the visible layout closely mirrors a mainstream social-media login page rather than an independent website with its own branding.
Based on the domain structure, this is a subdomain hosted on pages.dev, a static hosting platform. The hostname itself does not appear to match Facebook's official web properties, which raises concern that the page may be intended to imitate a well-known social platform rather than represent an authorized login portal.
The available content does not suggest a full social-media service or business website operated under its own identity. Instead, it appears to function primarily as a credential-entry page, which is commonly associated with account-harvesting or impersonation scenarios when presented on an unrelated domain.
Safety Assessment for sp11ct-ralvek-biz8-kormel-dasvik.pages.dev
Multiple scan signals indicate elevated risk at the time of this scan. The domain was flagged by 15 out of 91 security engines, with many of those detections classifying it as phishing or otherwise malicious. In addition, one phishing-focused threat database listed the domain, and the page content visibly imitates Facebook while being hosted on an unrelated pages.dev subdomain. That combination is a strong indicator that the site may be attempting to collect user credentials by impersonating a trusted service.
The malware scan did not report infected files, but it did mark the domain and several internal links with a generic suspicious heuristic. That clean file result does not offset the broader phishing indicators, because credential-harvesting pages often rely on ordinary web assets rather than traditional malware payloads. The domain's IP address is also listed on one mail-reputation blocklist, which is a weaker signal on its own but still adds minor caution.
The site uses a valid HTTPS certificate, but TLS alone does not verify legitimacy. Based on these findings and the visible resemblance to Facebook on a non-official domain, this website may pose potential risks to visitors.
Technical Description
The site is hosted behind Cloudflare infrastructure on IP address 172.66.47.43 and uses a valid SSL/TLS certificate issued by Google Trust Services, with expiry shown as 2026-10-26. The domain is a pages.dev subdomain and appears to be served through a static web hosting setup. DNSSEC is not enabled for the domain according to the provided data.
From a technical perspective, the main concern is not certificate validity but content and reputation signals: a login page imitating a major platform, multiple phishing detections from security engines, and a listing in a phishing-related database. The domain is several years old, but because it is a hosted subdomain rather than a standalone brand domain, age alone does not materially reduce the observed risk.
Share your experience with this website. Was it safe? Did you encounter any issues?