Facebook phishing and impersonation - 4 domains observed

MalwareAnalyzer by Cyble has observed 4 distinct domains impersonating Facebook across 7 URL scans. 4 of them carry a malicious or suspicious verdict, and the pages were built with the kit meta / facebook login kit. None of these domains belong to Facebook; they are sites impersonating it, detected by comparing a page's claimed identity against evidence of who actually operates it.

Facebook-branded phishing pages on compromised or third-party sites

These domains are NOT lookalikes of Facebook - most are legitimate sites that have been compromised, or free-hosting space, serving a page that presents Facebook branding in a credential or payment context. The domain owner is usually a victim too; each row is about the hosted page, never an accusation against the domain itself.

DomainWorst verdictEvidenceScansFirst seenLast seenKitExample page
denverbestlimoservice.shuttlebookingpro.netmaliciousphishing kit12026-08-202026-08-20meta / facebook login kithttps://denverbestlimoservice.shuttlebookingpro.net/
www.transpack-krumbach.desuspiciousphishing kit12026-08-202026-08-20meta / facebook login kithttps://www.transpack-krumba...manager/file/31793625601.pdf
dfdtrading.sksuspiciousphishing kit32026-08-162026-08-16meta / facebook login kithttps://dfdtrading.sk/ckfinder/userfiles/files/monoduxu.pdf
w01.chistogood.rususpiciousphishing kit22026-08-152026-08-15meta / facebook login kithttps://w01.chistogood.ru/ad...erfiles/files/goduvuzegu.pdf

Phishing kits used

Malware observed hosted on or communicating with these domains

None yet. That is the honest state, not a gap in the page: credential-harvesting phishing mostly collects logins rather than serving executables, so a domain can be actively hostile with no malware ever hosted on it. This section fills in only when a sample's runtime traffic, extracted configuration or download provenance evidences one of these domains - a hostname merely appearing inside a file's bytes is listed separately below and never counted here.

How impersonation is detected

A page's CLAIMED identity (its title, og:site_name, favicon and phishing-kit fingerprint) is compared against evidence of who actually operates it: the certificate subject organisation, the RDAP registrant and the announcing network. A free domain-validated certificate asserts nothing about ownership, and that asymmetry is itself the signal. A page on Facebook's own apex with a matching certificate organisation is treated as the real property, not an impersonation, which is why this list does not include Facebook's own sites.

These are point-in-time observations. A domain listed here may since have been taken down, and absence from this list is not evidence a domain is safe.

Questions about Facebook phishing

How many domains are impersonating Facebook?
4 distinct domains, seen across 7 public URL scans, of which 4 currently carry a malicious or suspicious verdict.
How can I tell a fake Facebook site from the real one?
Compare what the page CLAIMS against who demonstrably operates it: the certificate subject organisation, the domain's registrant and the network announcing its address. A free domain-validated certificate proves control of the name and nothing about ownership, and that asymmetry is the signal - a real Facebook property does not need to borrow the brand's look.
Which phishing kits target Facebook?
meta / facebook login kit (7 scans). A kit fingerprint means the page was built from a known toolkit rather than hand-made, which usually indicates a campaign rather than a one-off.
Is a domain safe if it is not listed here?
No. This lists what MalwareAnalyzer has scanned, not the whole internet, and a domain taken down yesterday still appears. Absence is not evidence of safety - scan the specific URL.

All brands under attack · Scan a URL · Latest analyzed threats · How URL scanning works