vormela-gld-belquro-c8x1hk34.pages.dev
Category: Phishing
To use full-featured product, you have to purchase a license for Combo Cleaner. Limited seven days free trial available. Combo Cleaner is owned and operated by RCS LT, the parent company of PCRisk.com.
Description of vormela-gld-belquro-c8x1hk34.pages.dev
This domain is hosted on the pages.dev platform and appears to present a login page styled to resemble Facebook. The page title is "Facebook," and the screenshot shows branding, layout, and account sign-in elements associated with Meta's social media service, including fields for email/mobile number and password.
Based on the visible content and URL structure, this does not appear to be an official Facebook or Meta-owned domain. Instead, it appears to be a third-party page deployed on a cloud hosting subdomain, potentially intended to imitate a familiar social platform login experience. The presence of an appeal-related path and a credential-entry form suggests it may be designed to collect account information from visitors.
Safety Assessment for vormela-gld-belquro-c8x1hk34.pages.dev
Multiple security signals indicate elevated risk at the time of this scan. The domain was flagged by 11 out of 91 security engines, with the detections largely classifying it as phishing or malicious. In addition, the page visually resembles Facebook while using an unrelated pages.dev subdomain, which may indicate an attempt to imitate a well-known service and capture login credentials.
Blacklist and reputation data were mixed but still concerning. While several threat databases did not report active malware distribution, one browser-protection style listing was present and the domain's IP address was also listed on one mail-reputation blocklist. The malware file scan itself did not detect malicious files, but that does not rule out credential-harvesting pages, which often rely on simple web forms rather than downloadable malware.
Given the combination of multi-engine phishing detections, the imitation of a major brand login page, and the lack of a legitimate brand-owned domain, this website may pose potential risks to visitors at the time of this scan.
Technical Description
The site is served over HTTPS with a valid TLS certificate issued by a mainstream certificate authority, and it is hosted behind Cloudflare infrastructure on IP address 172.66.47.104. The domain uses Cloudflare nameservers and appears to be deployed as a hosted subsite on the pages.dev platform. DNSSEC is not enabled for this hostname.
From a technical standpoint, the presence of valid SSL/TLS should not be treated as proof of legitimacy, since phishing pages commonly use HTTPS as well. The scan did not identify malicious files or flagged external links, but the page content, hosting model, and phishing detections from multiple security engines are the more significant concerns in this case.
Share your experience with this website. Was it safe? Did you encounter any issues?