04896b.icefactory.cl
Category: Malicious
To use full-featured product, you have to purchase a license for Combo Cleaner. Limited seven days free trial available. Combo Cleaner is owned and operated by RCS LT, the parent company of PCRisk.com.
Quttera Web Malware Removal is a paid subscription service. Pricing, plans, and trial availability are set by Quttera. Quttera is operated by Quttera Ltd, an independent third-party company unrelated to RCS LT. PCrisk.com may earn a referral commission when users sign up through this link.
Description of 04896b.icefactory.cl
This subdomain appears to host a page styled as an "Adobe Acrobat Reader" or "Secure PDF Document" access portal. Based on the page title, screenshot, and form layout, it is presenting itself as a document-viewing or document-access page that asks visitors to enter an email address before continuing to a PDF.
The domain itself is a subdomain of icefactory.cl, but the visible content does not appear to represent a normal corporate homepage or a clearly branded service operated by that organization. Instead, it appears to be a single-purpose landing page designed to imitate a document-sharing workflow, which is a pattern commonly associated with credential-harvesting campaigns. The available data does not identify a clear legitimate operator for this specific subdomain.
Safety Assessment for 04896b.icefactory.cl
Multiple security signals indicate elevated risk at the time of this scan. The URL was flagged by 16 out of 91 security engines, with many classifying it as phishing, fraud, or malicious activity. In addition, the screenshot shows a page imitating an Adobe-branded secure PDF access screen and prompting for an email address before document access, which may be consistent with an attempt to collect credentials or other sensitive information.
Blacklist and reputation data were mixed. Major content-malice databases in the provided scan were largely clean at the time of review, but the domain's IP address was listed on one mail-reputation blocklist, which is a weaker signal and does not by itself prove harmful website activity. Even so, the combination of broad multi-engine phishing detections, a very low trust score, and the impersonation-style page design materially increases concern.
Based on these findings, this website may pose potential risks to visitors, particularly if asked to enter login details, email credentials, or other personal information.
Technical Description
The site was reachable over HTTPS with a valid Let's Encrypt certificate that, at the time of this scan, was set to expire on 2026-11-08. It appears to be hosted on an Apache web server at IP address 186.64.119.45, operated by ZAM LTDA in Curicó, Chile. DNSSEC status was not confirmed in the provided data, and the domain uses nameservers under pymedns.net.
From a technical perspective, the presence of valid TLS only indicates encrypted transport and should not be treated as proof of legitimacy. The scanned path included a long, randomly structured URL and one file/path was flagged as suspicious by a malware scan, which may be consistent with disposable phishing infrastructure or a narrowly targeted landing page.
Share your experience with this website. Was it safe? Did you encounter any issues?