sp5ct-gonex-biz8-vurem-haliv.pages.dev
Category: Phishing
To use full-featured product, you have to purchase a license for Combo Cleaner. Limited seven days free trial available. Combo Cleaner is owned and operated by RCS LT, the parent company of PCRisk.com.
Description of sp5ct-gonex-biz8-vurem-haliv.pages.dev
This domain appears to host a page on the pages.dev platform, which is commonly used for static site deployments and web app hosting. Based on the page title and screenshot, the content presents itself as a Facebook login page, including branding elements, a sign-in form, and references to Meta-related navigation links.
However, the domain name itself does not appear to be an official Facebook or Meta-owned web address. The combination of a random-looking subdomain on a third-party hosting platform and a login interface for a major social media service suggests the page may be intended to imitate a legitimate account portal rather than serve as an official property operated by the brand it references.
Safety Assessment for sp5ct-gonex-biz8-vurem-haliv.pages.dev
Several security signals indicate elevated risk at the time of this scan. The domain was flagged by 13 out of 91 security engines, with multiple detections describing the page as phishing or otherwise malicious. In addition, the screenshot shows a login form branded as Facebook while being hosted on an unrelated pages.dev subdomain, which closely resembles an account-harvesting setup rather than a normal login flow. The presence of paths such as "appeals/submit-appeal-form" may also fit patterns sometimes used in social-engineering lures.
Blacklist and threat-database results were mixed. No threats were detected by several content-focused blacklist sources at the time of this scan, and the malware file scan did not identify malicious files. However, the domain's IP address is listed on one mail-reputation blocklist, which is a weaker signal on its own but still adds some caution. Taken together with the multi-engine phishing detections and the apparent imitation of Facebook branding on a non-official domain, the overall risk profile appears concerning.
Based on these findings, this website may pose potential risks to visitors.
Technical Description
The site uses a valid TLS certificate issued by a mainstream certificate authority, with expiry shown in October 2026. It is hosted through Cloudflare infrastructure on a pages.dev subdomain, with nameservers also delegated to Cloudflare. This setup is common for legitimate static hosting, but it can also be used by short-lived impersonation pages because deployment is fast and inexpensive.
The domain has existed for several years and is not newly registered, though that does not by itself reduce the phishing concern for a hosted subdomain. DNSSEC appears to be unsigned, and the web server software was not identified in the scan output. No malicious files or flagged external links were reported by the page-level malware scan, but the main technical concern remains the mismatch between the hosted domain and the branded login content.
Share your experience with this website. Was it safe? Did you encounter any issues?