usg-23up4-mcea1t-2e7cp-g6tdd6.pages.dev
Category: Phishing
To use full-featured product, you have to purchase a license for Combo Cleaner. Limited seven days free trial available. Combo Cleaner is owned and operated by RCS LT, the parent company of PCRisk.com.
Description of usg-23up4-mcea1t-2e7cp-g6tdd6.pages.dev
This domain appears to host a page designed to resemble Facebook's login interface. The page title is "Facebook," and the screenshot shows branding, layout, and account sign-in elements associated with Meta's social media platform rather than an independent service with its own identity.
The domain itself uses a pages.dev subdomain on Cloudflare's hosting platform, which is commonly used for static site deployment. Based on the visible content and URL structure, the page may be intended to collect login credentials or route visitors through an account-related workflow such as an appeal or sign-in process while presenting itself as a Facebook-related page.
There is no clear indication in the scan data that this is an official Meta-operated domain. Instead, the combination of a non-official host name, Facebook branding, and login prompts suggests the site may be imitating a well-known social media service.
Safety Assessment for usg-23up4-mcea1t-2e7cp-g6tdd6.pages.dev
Multiple security signals indicate elevated risk at the time of this scan. The domain was flagged by 12 out of 91 security engines, with several classifying it as phishing or otherwise malicious. In addition, the page visually presents itself as a Facebook login screen while operating from a pages.dev subdomain that does not appear to be an official Facebook or Meta web address. That mismatch is a strong indicator that the site may be attempting to imitate a trusted brand.
Blacklist and threat-database results were mixed. Major content-focused threat databases in the provided scan were clean at the time of this scan, but the domain's IP address was listed on one mail-reputation blocklist, which is a weaker signal and does not by itself prove harmful website activity. The malware file scan did not detect flagged files, but clean file results do not outweigh the stronger phishing indicators when the page content itself appears to mimic a login portal.
Taken together, the branding mismatch, credential-entry form, lack of established reputation, and multi-engine phishing detections suggest a meaningful likelihood of deceptive intent. Based on these findings, this website may pose potential risks to visitors.
Technical Description
The site is hosted behind Cloudflare infrastructure on IP address 172.66.44.79, with nameservers also delegated to Cloudflare. It presents a valid SSL/TLS certificate issued by Google Trust Services, which means the connection appears encrypted in transit; however, valid HTTPS does not by itself indicate legitimacy. DNSSEC appears to be unsigned.
The server stack is partially obscured by the hosting platform, and the scan did not identify a specific origin web server. The domain is about five years old, but because this is a pages.dev subdomain, the age of the parent registration does not necessarily reflect the age or trustworthiness of the specific hosted content. A notable technical concern is the use of a third-party hosting subdomain to present a login page for a major brand, which may be inconsistent with expected official infrastructure.
Share your experience with this website. Was it safe? Did you encounter any issues?