Phishing detection: facebookdl.pages.dev

Facebook
https://facebookdl.pages.dev Access site
Screenshot
No screenshot available yet Captured automatically on the next refresh cycle
Investigate
Domain facebookdl.pages.dev1 CT host on apex
URL https://facebookdl.pages.dev
Cert Google Trust Services
Phishunt analysis Beta
29 low suspicionheuristic risk score · not a probability
Why?
  • +5.3 Keyword match
  • +5.1 Site cluster
  • +5.1 urlscan.io
  • +4.5 Brand in title
  • +3.7 Brand in domain label
  • +1.1 ASN reputation
  • +1.1 No CSP header
  • +1.1 No HSTS header
  • +0.7 Brand in cert SAN
  • +0.6 Suspicious TLD
  • +0.5 Young certificate
  • +0.4 Long domain
  • +0.3 Free CA
  • +0.1 Deep subdomain
17 signals fired · detector v3.0.0
AI analysis AIBeta
Credential harvesting

Site impersonating Facebook on a Cloudflare Pages subdomain whose download-suggestive name may indicate credential harvesting or malicious content delivery under the Facebook brand. Flagged as malicious by urlscan, with the brand embedded directly in the apex label and no security headers present.

urlscan.ioBrand in domain labelKeyword match
AI-generated from stored detector signals - the AI never visited the site. · 2026-08-04 · confidence 74%
Domain & Network
Whois
Registrar CloudFlare, Inc.
Network
Country United StatesUnited States
ASN AS13335
External detection urlscan.io
CleanGoogle Safe Browsing · OpenPhish · PhishTank · TweetFeed
Report this phishing
PaaS platform Cloudflare Pages
Registrar CloudFlare, Inc.

Tracked from 2026-08-04 03:02 UTC  ·  Last refreshed 2026-08-25 03:30 UTC