xelquza-gld-larnemi-c2p8hq53.pages.dev
Category: Phishing
To use full-featured product, you have to purchase a license for Combo Cleaner. Limited seven days free trial available. Combo Cleaner is owned and operated by RCS LT, the parent company of PCRisk.com.
Description of xelquza-gld-larnemi-c2p8hq53.pages.dev
This domain appears to host a page designed to resemble Facebook's login interface, including Facebook branding, a login form, and Meta-related footer links. The page title is "Facebook," and the visible content suggests it is attempting to present itself as an account sign-in or account recovery page rather than as an independent website with its own brand identity.
The domain itself is a random-looking subdomain under pages.dev, which is a hosted web platform rather than an official Facebook-owned domain. Based on the screenshot and URL structure, the page may be intended to collect user credentials or appeal-form submissions while imitating a well-known social media service.
Safety Assessment for xelquza-gld-larnemi-c2p8hq53.pages.dev
Multiple security signals indicate elevated risk at the time of this scan. The domain was flagged by 13 out of 91 security engines, with the detections broadly classifying it as phishing or otherwise malicious. In addition, the page visually imitates Facebook while being hosted on an unrelated pages.dev subdomain, which is a strong sign that it may be attempting to mislead visitors into entering account credentials or other sensitive information.
Although the malware scan did not detect malicious files in the sampled page resources, that does not offset the stronger phishing indicators. The domain's IP address is also listed on one mail-reputation blocklist, which is a weaker signal on its own but still worth noting. The combination of multi-engine phishing detections, impersonation of a major platform, lack of meaningful independent site identity, and a very low published trust score suggests a substantial likelihood of abuse.
Based on these findings, this website may pose potential risks to visitors.
Technical Description
The site uses a valid SSL/TLS certificate issued by Google Trust Services, and it is hosted behind Cloudflare infrastructure on an IP located in Canada. The domain is a pages.dev subdomain rather than a standalone branded domain, and the certificate validity only indicates encrypted transport, not legitimacy of the page content.
DNSSEC appears to be unsigned, and the web server software was not identified in the scan data. The page references standard static assets and a form-related path such as /send_appeal_request, which is consistent with a credential-harvesting or account-themed workflow. From a technical perspective, the main concern is not malware delivery but the apparent use of hosted infrastructure to present a convincing imitation login page.
Share your experience with this website. Was it safe? Did you encounter any issues?