0f980b.icefactory.cl
Category: Phishing
To use full-featured product, you have to purchase a license for Combo Cleaner. Limited seven days free trial available. Combo Cleaner is owned and operated by RCS LT, the parent company of PCRisk.com.
Quttera Web Malware Removal is a paid subscription service. Pricing, plans, and trial availability are set by Quttera. Quttera is operated by Quttera Ltd, an independent third-party company unrelated to RCS LT. PCrisk.com may earn a referral commission when users sign up through this link.
Description of 0f980b.icefactory.cl
This URL appears to be a subdomain hosted under icefactory.cl rather than a standalone branded website. Based on the page title and screenshot, it presents itself as an "Adobe Acrobat" or "secure PDF document" access page and prompts visitors to enter an email address before continuing. The subdomain name itself is random-looking, which is not typical of a public-facing business or document-sharing portal.
The visible content does not suggest a normal corporate homepage, publisher site, or consumer service. Instead, it appears to be a single-purpose landing page designed to imitate a document-access workflow. Based on the available page elements, the operator is not clearly identified on the page, and there is no obvious indication that Adobe operates this specific subdomain.
Safety Assessment for 0f980b.icefactory.cl
Multiple scan signals indicate elevated risk at the time of this scan. The URL was flagged by 18 out of 91 security engines, with many of those detections classifying it as phishing or malicious. In addition, the screenshot shows a page styled as an Adobe Acrobat document-access prompt asking for an email address, which may be consistent with credential-harvesting or deceptive document-delivery tactics. The very low trust score provided with the scan also aligns with that assessment.
Blacklist and threat-database results were mixed rather than uniformly clean. Major content-malice databases shown here did not detect the domain at the time of the scan, but the domain's IP address was listed on one mail-reputation blocklist, which is a weaker signal and does not by itself prove harmful website activity. A separate malware scan also returned a generic suspicious result on one scanned path, adding a small amount of corroboration.
Although the parent domain is several years old and the site uses valid HTTPS, those factors do not outweigh the combination of multi-engine phishing detections and the deceptive-looking login-style document page. Based on these findings, this website may pose potential risks to visitors.
Technical Description
The site was reachable over HTTPS with a valid Let's Encrypt certificate that, at the time of the scan, was set to expire on 2026-11-08. It appears to be hosted on an Apache web server at IP address 186.64.119.45, with hosting attributed to ZAM LTDA in Curicó, Chile. DNSSEC status was reported as unknown, and the domain uses ns1.pymedns.net, ns2.pymedns.net, and ns3.pymedns.net as nameservers.
From a technical perspective, the presence of TLS only indicates encrypted transport and should not be treated as proof of legitimacy. The use of a random-looking subdomain and a suspicious deep path, combined with phishing-oriented page content, may indicate a compromised host, disposable subdomain, or attacker-controlled content placed on otherwise ordinary infrastructure.
Share your experience with this website. Was it safe? Did you encounter any issues?