sp4ct-elvurin-biz8-kurem-dazok.pages.dev
Category: Phishing
To use full-featured product, you have to purchase a license for Combo Cleaner. Limited seven days free trial available. Combo Cleaner is owned and operated by RCS LT, the parent company of PCRisk.com.
Description of sp4ct-elvurin-biz8-kurem-dazok.pages.dev
This domain appears to host a page designed to resemble Facebook's login interface, including Facebook branding, a Meta footer, and fields for email/phone and password entry. The page title is "Facebook," and the screenshot shows a layout closely matching a social-media account sign-in page rather than an independent website with its own brand identity.
The domain itself is a long, random-looking subdomain under pages.dev, which is a static hosting platform commonly used for lightweight web deployments. Based on the visible content and URL structure, the page may be intended to collect account credentials or route visitors through an appeal or login-related workflow while presenting itself as associated with Facebook or Meta.
There is no clear indication from the domain name that this page is officially operated by Meta. Based on the available content, it appears to be an unofficial page imitating a well-known social-media service.
Safety Assessment for sp4ct-elvurin-biz8-kurem-dazok.pages.dev
Multiple warning signs were present at the time of this scan. The domain was flagged by 14 out of 91 security engines, with many of those detections classifying it as phishing or otherwise malicious. In addition, the page visually imitates Facebook's login screen while using an unrelated pages.dev subdomain, which may indicate an attempt to capture user credentials by resembling a trusted brand.
Blacklist and threat-database results were mixed. Several major content-focused threat databases did not list the domain at the time of this scan, and the malware file scan did not detect malicious files in the sampled content. However, the domain's IP address was listed on one mail-reputation blocklist, which is a weaker signal than direct phishing detections but still worth noting as a minor caution.
Taken together, the strongest indicators here are the multi-engine phishing consensus and the visible imitation of a well-known login page on an unrelated host. Based on these findings, this website may pose potential risks to visitors.
Technical Description
The site uses a valid SSL/TLS certificate issued by a mainstream certificate provider, with expiry shown as 2026-10-19. It is hosted through Cloudflare infrastructure on IP address 188.114.96.2, with nameservers also delegated to Cloudflare. DNSSEC appears to be unsigned, which is not uncommon but does mean DNS responses do not benefit from DNSSEC validation.
From a hosting perspective, this appears to be a static page deployment on pages.dev rather than a dedicated standalone server. The technical setup itself does not confirm abuse, but the combination of a random-looking subdomain, brand-mimicking content, and phishing detections raises concern about how the hosted page may be being used.
Share your experience with this website. Was it safe? Did you encounter any issues?