10thys5jkoo3.swjaxonfivs.xyz
Category: Phishing
To use full-featured product, you have to purchase a license for Combo Cleaner. Limited seven days free trial available. Combo Cleaner is owned and operated by RCS LT, the parent company of PCRisk.com.
Description of 10thys5jkoo3.swjaxonfivs.xyz
This domain appears to be a newly created website hosted on a random-looking subdomain under swjaxonfivs.xyz, with no established traffic ranking and very limited identifying information about any legitimate operator. The page title references Google, while the visible page content imitates a Microsoft Outlook/Office-style interface and presents a completed download message for a ZIP archive named "SWIFT_MT103_PAYMENT(40464).zip." Based on the domain structure, branding mismatch, and page presentation, the site appears to be designed to mimic a familiar business or productivity environment rather than represent a transparent standalone service.
The content shown in the screenshot suggests the page may be used as part of a social-engineering workflow, potentially encouraging visitors to trust or open a downloaded file related to payments or financial documents. The use of Outlook and Office visual elements, combined with a finance-themed filename, may indicate an attempt to impersonate a business communication or document-delivery process. No clear ownership, company identity, or legitimate service description is visible on the page at the time of this scan.
Safety Assessment for 10thys5jkoo3.swjaxonfivs.xyz
Multiple security signals indicate elevated risk at the time of this scan. The domain was flagged by 13 out of 91 security engines, with many of those detections classifying it as phishing or fraud-related. In addition, several web-classification sources categorized the site as phishing, and the screenshot shows branding and interface elements that resemble well-known productivity and email services while being hosted on an unrelated, newly registered domain. That combination may be consistent with credential theft, deceptive file delivery, or other social-engineering activity.
The domain is only 4 days old, has no meaningful traffic presence, and uses a random-looking hostname pattern that does not align with the brands visually referenced on the page. Although the malware scan did not identify flagged files at the time of inspection, that does not outweigh the broader phishing-related detections and the suspicious page design. The domain's IP address is also listed on one mail-reputation blocklist, which is a weaker signal than phishing detections but still adds some caution.
Based on these findings, this website may pose potential risks to visitors.
Technical Description
The site uses a valid SSL/TLS certificate issued by a mainstream certificate provider, expiring on 2026-10-23, and is routed through Cloudflare infrastructure with a reported server IP of 188.114.96.0 and a gws web server banner. The nameservers are also on Cloudflare, suggesting the domain is using a CDN or reverse-proxy layer. A valid certificate indicates encrypted transport, but it should not be treated as evidence of legitimacy on its own.
From a domain-security perspective, the registration is very recent, DNSSEC appears to be unsigned, and the hosting setup may make origin attribution less transparent. The visible URL path includes a challenge-platform endpoint, which can occur behind anti-bot or edge-delivery systems, but the page content itself remains the more significant concern here due to its apparent impersonation-style presentation and phishing-related detections.
Share your experience with this website. Was it safe? Did you encounter any issues?