Security Scan Report: facebook-downloader.bulkcreator.com

Redirected to:
https://facebook-downloader.bulkcreator.com/
Submitted: May 9, 2026, 12:51:37 PMCompleted: May 9, 2026, 12:53:08 PMpubliccompleted
Loading additional data...

Summary

This website contacted 5 IPs in 2 countries across 6 domains to perform 22 HTTP transactions. The main domain is facebook-downloader.bulkcreator.com and was registered NaN years ago.

Submitted URL: http://facebook-downloader.bulkcreator.com/

Effective URL: https://facebook-downloader.bulkcreator.com/Redirected

AI Security Verdict

Confirmed Scam

Confidence: 94%

9
Risk Score

The site pretends to be a Facebook downloader, uses eval() scripts and triggers a critical C2 beacon, indicating confirmed malicious activity.

Risk Factors
Brand impersonation / typosquatting
Critical malware C2 beacon alert
Unranked domain claiming a major brand
Dynamic eval() usage in JavaScript
Presence of advertising and upgrade prompts without legitimate functionality
Domain age information unavailable

Details

Page Title

Facebook Downloader - BulkCreator

Scan Type

public

Language

🇺🇸

English

(80% confidence)

Category

technology software

(34%)

Domain Information

The domain 'facebook-downloader.bulkcreator.com' uses the commercial generic top-level domain (.com) and includes subdomain 'facebook-downloader'. The core label 'bulkcreator' covers 11 characters containing four vowels alongside 7 consonants. Splitting it apart reveals two words: bulk, creator. Average segment length settles at 5.5 characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of http://facebook-downloader.bulkcreator.com/

Page Load Overview

1.45s
Total Load Time
46
HTTP Requests
9
Domains
974 KB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

Language Code:en
Detection Confidence:80%
Script Type:Latin
HTML Lang Attribute:en
Text Length:3,460 chars
Detector Agreement:100%

Website Classification

Primary Category

technology software34% confidence
Type: dynamic
Method: ml+structural

All Detected Categories

technology software
34%
documentation technical
30%

Detected Features

No structural features detected

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
10142.251.110.154United States
AS15169Google LLC
9142.251.14.95United States
AS15169Google LLC
9142.251.13.97United States
AS15169Google LLC
9192.178.183.94United States
AS15169Google LLC
967.43.225.66Canada
AS36666GloboTech Communications
465--

Detected Technologies2

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T146231A1665F214016053D1B4B773EB4A3B30C007C60ED9783FAD96A4EF8EAA5A9736DC

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

768:jJrUKeQ+pRbyCXJuviFGQXr2hLQu6f/YaITY3FTGt:FX+pRbyCXJuviwy2XoITYMt

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:49347:AguIxAYKUIURAtYQoBSIGgyUGiAELCgQQigIepOqapQCcEiAFBCAA0UGmMCeQaSFg1VImBFCoAQVUIkGNKQLI4SsIUAxAzEY

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:e7fff9f9f9f9f9f9
Perceptual Hash:e9969636366934e1
Difference Hash:0c2c331333331313
Wavelet Hash:008e98f89999f9f9
Color Hash:#5396ac

Scan History

Scan history not available

Unable to load historical scan data