18mo.xyz
Category: Phishing
To use full-featured product, you have to purchase a license for Combo Cleaner. Limited seven days free trial available. Combo Cleaner is owned and operated by RCS LT, the parent company of PCRisk.com.
Description of 18mo.xyz
18mo.xyz appears to be a Chinese-language profile or fan-page style website centered on a persona identified as "momo-5952." The page title and metadata describe live streams, videos, and image galleries, and the homepage screenshot shows a profile-style landing page with a call-to-action to watch a live stream. Based on the visible content and linked paths, the site may function as a traffic funnel to media or adult-oriented content rather than as a broad informational website.
The domain itself is very new and does not appear to have an established public traffic ranking. Ownership details are limited to registrar and infrastructure records, and the site is fronted by a content delivery and reverse-proxy service, which can obscure the origin server. Based on the screenshot and metadata, the operator is not clearly identified on the page, so the entity behind the website cannot be confidently verified from the available data.
Safety Assessment for 18mo.xyz
This domain shows multiple risk indicators at the time of this scan. It was flagged by 13 out of 91 security engines, with several detections describing phishing or malicious behavior. In addition, major threat-database checks included a listing for social-engineering activity, and another blacklist source also returned a malicious-style classification. While one malware scan reported no flagged files, it still attached a generic malicious label to the domain and several internal URLs, which adds to the overall caution rather than offsetting the broader consensus.
Context also matters here: the domain is only 148 days old, has no visible traffic ranking, and presents a minimal landing page that promotes live viewing and media content with limited operator transparency. The screenshot contains sexualized imagery, and the site links out through tracking and sharing URLs, which may be consistent with aggressive traffic-redirection patterns. Based on these findings, this website may pose potential risks to visitors.
Because these are point-in-time results, they should be interpreted as current scan findings rather than a permanent verdict. However, based on available scan data, the combination of multi-engine phishing detections, social-engineering blacklist presence, and a very new domain suggests a high-risk profile at the time of this scan.
Technical Description
The site uses a valid SSL/TLS certificate issued by a mainstream certificate authority, and traffic appears to be proxied through Cloudflare infrastructure on IP address 172.67.205.113, geolocated here to Toronto, Canada. Nameservers are also on Cloudflare, and the web server is reported as Cloudflare. The certificate being valid helps with transport encryption, but it does not by itself indicate trustworthiness of the site content.
From a domain-security perspective, DNSSEC is not enabled, and the domain is very recently registered. No DNS-based mail-reputation blocklist hits were reported in this scan. The main technical concerns are therefore not certificate-related, but rather the combination of new registration age, obscured origin hosting behind a reverse proxy, and the adverse reputation signals returned by multiple security systems.
Share your experience with this website. Was it safe? Did you encounter any issues?