xelmavi-vrk-belquna-p2t9dk81.pages.dev
Category: Phishing And Fraud
To use full-featured product, you have to purchase a license for Combo Cleaner. Limited seven days free trial available. Combo Cleaner is owned and operated by RCS LT, the parent company of PCRisk.com.
Description of xelmavi-vrk-belquna-p2t9dk81.pages.dev
This domain is hosted on the pages.dev platform and appears to present itself as a Facebook login page. The page title is "Facebook," and the screenshot shows a sign-in form styled to resemble Facebook's branding, including Meta references and familiar account-login elements. Based on the visible content, the site appears intended to collect user login details rather than provide independent original content.
The domain name itself is a long, random-looking subdomain rather than an official Facebook or Meta web address. That mismatch, combined with the social-media themed page content and the visible login form, suggests the page may be imitating a well-known platform. Based on available data, it does not appear to be operated by Facebook or Meta, but instead by an unrelated party using a cloud-hosted deployment.
Safety Assessment for xelmavi-vrk-belquna-p2t9dk81.pages.dev
Multiple security signals indicate elevated risk at the time of this scan. The domain was flagged by 9 out of 91 security engines, with several classifying it as phishing-related, and multiple web-classification providers associated it with phishing, fraud, or social-media themed content. The screenshot also shows a login page that closely imitates Facebook while using an unrelated pages.dev subdomain, which may indicate an attempt to capture credentials by resembling a trusted brand.
The malware file scan did not detect malicious files at the time of analysis, and several major threat databases were clean. However, one blacklist entry reported a generic suspicious listing, and the domain's IP address is listed on one mail-reputation blocklist, which is a weaker signal but still worth noting. In this case, those cleaner signals are outweighed by the multi-engine phishing detections and the visible brand imitation on the page.
Based on these findings, this website may pose potential risks to visitors.
Technical Description
The site uses a valid SSL/TLS certificate issued by Google Trust Services, with hosting and DNS infrastructure routed through Cloudflare. The resolved IP address is 172.66.47.44, geolocated to Toronto, Canada based on available hosting data. The domain has been registered since 2020 and is set to expire in 2027, which means it is not a newly created domain even though the current subpage content may be recent.
DNSSEC appears to be unsigned, and the web server software was not identified in the scan data. The use of a reputable CDN and a valid certificate helps with transport encryption, but those technical factors do not by themselves verify legitimacy. The main technical concern here is the apparent use of a cloud-hosted subdomain to present a login page resembling a major social platform.
Share your experience with this website. Was it safe? Did you encounter any issues?