Phishing detection: 393bet-facebook.sa.com
Facebook Investigate
Domain
393bet-facebook.sa.com1 CT host on apex
IP
188.114.97.3
URL
https://393bet-facebook.sa.com
Cert
Google Trust Services
Phishunt analysis Beta
35
medium suspicion suspiciousheuristic risk score · not a probability
Why?
- +5.3 Keyword match
- +5.1 Site cluster
- +5.1 urlscan.io
- +4.5 Brand in title
- +4.1 Brand in screenshot
- +3.4 Shared IP cluster
- +2.1 ASN reputation
- +1.1 No CSP header
- +1.1 No HSTS header
- +0.7 Brand in cert SAN
- +0.6 Login text in screenshot
- +0.6 Suspicious TLD
- +0.5 Young certificate
- +0.5 Long domain
- +0.3 Free CA
- +0.2 External scripts
- +0.1 Hyphens
- +0.1 Deep subdomain
22 signals fired · detector v3.0.0
AI analysis AIBeta
Credential harvesting
Impersonates Facebook while combining a gambling brand name in the domain, with login keywords detected in the page. Hosted on Cloudflare infrastructure and flagged by urlscan as malicious. Likely harvests Facebook credentials while redirecting victims toward a fraudulent betting platform.
urlscan.ioLogin text in screenshotKeyword match
AI-generated from stored detector signals - the AI never visited the site. · 2026-07-23 · confidence 80%
Domain & Network
Whois
Registrar
Sav.com, LLC
Network
IP
188.114.97.3
Country
United States
Hosting
Cloudflare, Inc.
ASN
AS13335
TLS Cert
Google Trust Services
External detection
urlscan.io
CleanGoogle Safe Browsing · OpenPhish · PhishTank · TweetFeed
Requests
Resources
Observables
Related websites
Report this phishing
Submit to blocklists
urlscan
VirusTotal
Whois
ipinfo
Greynoise