xlbdw5avstr-ycgfnmja-8d9e2f-xlq20c.pages.dev
Category: Phishing And Fraud
To use full-featured product, you have to purchase a license for Combo Cleaner. Limited seven days free trial available. Combo Cleaner is owned and operated by RCS LT, the parent company of PCRisk.com.
Description of xlbdw5avstr-ycgfnmja-8d9e2f-xlq20c.pages.dev
This domain is hosted on the pages.dev platform and appears to present a login page styled to resemble Facebook, including Facebook branding, a Meta footer, and account sign-in fields. The page title is "Facebook," and the visible content suggests it is attempting to imitate a social media login experience rather than operate as an independent branded service.
Based on the domain structure and page content, this does not appear to be an official Facebook or Meta-owned domain. The long, random-looking subdomain string and the presence of paths such as "send_appeal_request" and "submit-appeal-form" may indicate a credential-harvesting or account-appeal themed landing page designed to collect user information.
Safety Assessment for xlbdw5avstr-ycgfnmja-8d9e2f-xlq20c.pages.dev
Multiple security signals raise concern about this domain at the time of this scan. It was flagged by 11 out of 91 security engines, with several classifying it as phishing-related, and multiple web-classification sources associated it with phishing, fraud, or social-media-themed content. The screenshot also shows a Facebook-branded login form hosted on a non-Facebook domain, which closely resembles the legitimate service and may be intended to mislead visitors into entering account credentials.
Blacklist data was mixed at the time of this scan. Major content-malice databases shown in the scan were largely clean, but one blacklist entry indicated a suspicious-object listing, and the domain's IP address was also listed on one mail-reputation blocklist. While a DNS-based mail-reputation listing alone would be a weak signal, it adds minor caution when combined with the stronger phishing indicators above.
The malware file scan did not detect malicious files in the sampled content, but that does not offset the broader phishing-related indicators and the apparent imitation of a well-known login page. Based on these findings, this website may pose potential risks to visitors.
Technical Description
The site uses a valid TLS certificate issued by Google Trust Services, with certificate expiry extending to 2026-11-03. It is hosted behind Cloudflare infrastructure on IP address 172.66.47.126, with Cloudflare nameservers and a registrar also associated with Cloudflare. The domain itself is several years old, although that age may reflect the pages.dev subdomain registration rather than trustworthiness of the specific content currently served.
DNSSEC appears to be unsigned at the time of this scan. The web server software and supported protocol details were not identified in the provided data. No malicious files were flagged in the limited file scan, but the main technical concern is not exploit delivery; it is the apparent use of a cloud-hosted page to mimic a well-known login portal.
Share your experience with this website. Was it safe? Did you encounter any issues?