vnzkt7e52dr-hbkptlpw-6a5b0c-hb699a.pages.dev
Category: Phishing
To use full-featured product, you have to purchase a license for Combo Cleaner. Limited seven days free trial available. Combo Cleaner is owned and operated by RCS LT, the parent company of PCRisk.com.
Description of vnzkt7e52dr-hbkptlpw-6a5b0c-hb699a.pages.dev
This domain appears to be hosted on a pages.dev subdomain associated with a static-site hosting platform rather than on an official branded domain. Based on the page title, screenshot, and visible interface elements, the page is presenting itself as a Facebook login screen and uses branding associated with Meta's social media services.
The content shown includes a username/email field, password field, login button, and links styled to resemble Facebook account access and recovery options. The domain name itself is a long, random-looking string that does not match Facebook's official web properties, which suggests this page may be intended to imitate a legitimate social media login experience rather than serve as an independently branded website.
Safety Assessment for vnzkt7e52dr-hbkptlpw-6a5b0c-hb699a.pages.dev
Multiple security signals indicate elevated risk at the time of this scan. The domain was flagged by 14 out of 91 security engines, with detections broadly describing phishing or malicious behavior. In addition, the screenshot shows a login page visually resembling Facebook while being hosted on an unrelated pages.dev subdomain, which may indicate an attempt to collect account credentials by imitating a well-known service.
Blacklist and reputation data were mixed rather than fully clean. While several threat databases did not report active listings, one mail-reputation blocklist listed the domain's IP address, and one blacklist source also returned a suspicious listing. The malware file scan did not detect malicious files, but that does not rule out credential-harvesting pages, which often rely on deceptive page content rather than downloadable malware.
The domain is several years old and uses valid HTTPS, but those factors do not outweigh the phishing-style presentation, the unrelated hosting domain, and the multi-engine detection consensus. Based on these findings, this website may pose potential risks to visitors.
Technical Description
The site is served over HTTPS with a valid TLS certificate issued by a mainstream certificate authority, and the certificate was valid at the time of this scan. It appears to be hosted through Cloudflare infrastructure on IP address 188.114.96.2, with Cloudflare nameservers and a pages.dev deployment pattern consistent with static hosting.
DNSSEC appears to be unsigned, which is not uncommon but does mean DNS responses do not benefit from DNSSEC validation. The server software and negotiated protocol were not identified in the scan output. No malicious files or flagged external links were detected in the page resource scan, but the presence of an apparent credential form on a non-official branded domain is a more significant concern than the underlying hosting setup alone.
Share your experience with this website. Was it safe? Did you encounter any issues?