Security Scan Report: navravi-mpt-belmuzo-g7d4fa19.pages.dev

Site favicon
Submitted: Sep 27, 2026, 12:45:22 AMCompleted: Sep 27, 2026, 12:46:31 AMpubliccompleted

AI Security Verdict

Confirmed Scam

Confidence: 93%

9
Risk Score

Analyst-vetted Meta 'Page Appeal' credential-phishing kit on a disposable pages.dev subdomain, impersonating Meta Business with a 48-hour account-suspension scare to drive victims to a fake appeal submission.

Risk Factors (5)
Known malicious credential-phishing kit (meta-page-appeal family) confirmed by analyst-vetted kit roster
Impersonation of Meta/Facebook Business on a non-Meta domain (pages.dev)
False account-suspension threat with 48-hour enforcement deadline and fake Case ID to force compliance
Anti-analysis cloaking behaviour (redirect to real facebook.com for datacenter IPs, blank decoy for scanners)
Disposable shared-hosting subdomain with no reputation and meta description left at create-react-app default
Domain age information unavailable

Details

Page Title

Meta for Business | Page Appeal

Scan Type

public

Domain Name Analysis

The domain 'navravi-mpt-belmuzo-g7d4fa19.pages.dev' uses the developer-focused generic top-level domain (.dev), featuring subdomain 'navravi-mpt-belmuzo-g7d4fa19'. The second-level label 'pages' is 5 characters long split between 2 vowels and three consonants. Segmentation suggests 1 word: pages. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://navravi-mpt-belmuzo-g7d4fa19.pages.dev/send_appeal_request

Page Load Overview

5.05s
Total Load Time
224 KB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

HTML Lang Attribute:en
Text Length:3,640 chars
Detector Agreement:75%

Website Classification

Primary Category

social media network87% confidence
Type: static
Method: ml+structural

All Detected Categories

social media network
87%
technology software
57%
documentation technical
51%
adult content
48%
government public service
46%

Detected Features

No structural features detected

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
4188.114.97.9Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
1157.240.0.6Facebook · CDNFrankfurt am Main, Hesse, Germany
AS32934Facebook, Inc.
1157.240.0.13Facebook · CDNFrankfurt am Main, Hesse, Germany
AS32934Facebook, Inc.
1104.26.0.100Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
1188.114.96.9Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
1104.26.1.100Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
96--

Detected Technologies3

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T147A209B065B9236E568783F9651B63E821AE651FF2738050F6FC02B957CACD2FD23580

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

384:MAoS10lNvEiVDJVAFZnuyr178pS/BHYO86tM79/+ATcf2W++TaDv:MAmlNvEiVDTmuy578pS/ZYiIcf2W+++j

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:22095:AawAnkgWKSjMZBCHFIjQCFoEAGBVEiSIIITQhTikMEB4DgGNFgQQEHRCSAlCxjDUBWobjJjfgEfYILSAHGJVksAkSqxQARG8

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:c3c3dfdfe7e7e7e3
Perceptual Hash:e7656593989a9a98
Difference Hash:2e062c2c0e4c4c4e
Wavelet Hash:8e828286c7e3e7e3
Color Hash:#8f1f93

Other Hashes

Crop Resistant:2e062c2c0e4c4c4e

Scan History

Scan history not available

Unable to load historical scan data