tcy6-1n0-emeco-qbv7ql-qmsr5f.pages.dev
Category: Phishing
To use full-featured product, you have to purchase a license for Combo Cleaner. Limited seven days free trial available. Combo Cleaner is owned and operated by RCS LT, the parent company of PCRisk.com.
Description of tcy6-1n0-emeco-qbv7ql-qmsr5f.pages.dev
This domain appears to be hosted on pages.dev, a static-site hosting platform commonly used to publish lightweight web applications and landing pages. Based on the screenshot and page title, the site presents itself as a Facebook login page, using Facebook and Meta branding, a familiar sign-in layout, and account-access prompts.
The domain name itself does not appear to be an official Facebook or Meta web address. Instead, it uses a random-looking subdomain string under a hosting provider's shared domain, which may indicate a temporary or disposable deployment rather than an official corporate property. The presence of paths such as "/appeals/submit-appeal-form/return" and "/send_appeal_request" suggests the page may be designed to collect account-related information under the appearance of an appeal or login workflow.
Safety Assessment for tcy6-1n0-emeco-qbv7ql-qmsr5f.pages.dev
Multiple warning signs were identified at the time of this scan. The page visually imitates Facebook's login interface, but it is hosted on an unrelated pages.dev subdomain rather than an official Facebook or Meta domain. In addition, 12 out of 91 security engines flagged the URL, largely with phishing-related verdicts. That level of multi-engine agreement is a meaningful risk indicator, especially when combined with a login form requesting credentials for a well-known platform.
Blacklist and threat-database checks were mixed rather than fully clean. Major content-malice databases in the provided data did not report the domain at the time of this scan, but the domain's IP address was listed on one mail-reputation blocklist. That DNS-based listing is a weaker signal than direct phishing detections, yet it adds a small amount of caution rather than reassurance.
Taken together, the branding mismatch, credential-collection interface, and broad phishing consensus across security engines suggest this page may be intended to impersonate Facebook and capture user login details. Based on these findings, this website may pose potential risks to visitors.
Technical Description
The site uses a valid TLS certificate issued by a mainstream certificate authority, with expiry shown as 2026-10-19. However, a valid certificate only indicates encrypted transport and does not verify that the page is an official Facebook or Meta property. The domain is hosted through Cloudflare infrastructure on IP address 188.114.97.2, with nameservers also delegated to Cloudflare.
The domain record shows an age of about five years, but because this is a subdomain on pages.dev, the visible page content may have been deployed much more recently than the parent registration date suggests. DNSSEC appears to be unsigned, and the web server software was not identified in the scan data. The main technical concern is not TLS configuration but the apparent use of a hosted subdomain to present a branded login page that may not belong to the brand being displayed.
Share your experience with this website. Was it safe? Did you encounter any issues?