1fba23.icefactory.cl
Category: Malicious
To use full-featured product, you have to purchase a license for Combo Cleaner. Limited seven days free trial available. Combo Cleaner is owned and operated by RCS LT, the parent company of PCRisk.com.
Quttera Web Malware Removal is a paid subscription service. Pricing, plans, and trial availability are set by Quttera. Quttera is operated by Quttera Ltd, an independent third-party company unrelated to RCS LT. PCrisk.com may earn a referral commission when users sign up through this link.
Description of 1fba23.icefactory.cl
This subdomain appears to host a single-purpose web page presented as an "Adobe Acrobat" or "secure PDF document" access portal. Based on the page title, screenshot, and the lack of broader site content, it does not appear to function as a normal corporate or informational website. Instead, it seems designed to prompt visitors to enter an email address before continuing to a supposed document.
Safety Assessment for 1fba23.icefactory.cl
Multiple indicators suggest elevated risk at the time of this scan. The domain was flagged by 14 out of 91 security engines, with several classifying it as phishing, fraud, or malware-related. In addition, the visible page imitates an Adobe-branded document access screen and asks for an email address to open a purported PDF, which is a common credential-harvesting pattern. The site was also categorized by multiple web-classification providers as malicious or phishing-related.
A malware scan also reported a suspicious flagged path, although no specific malware family name was provided. Separately, the domain's IP address is listed on one mail-reputation blocklist, which is a weaker signal than direct phishing detections but still adds some caution. While some major threat databases were clean at the time of this scan, the combination of multi-engine phishing detections and the deceptive-looking login prompt materially outweighs those clean results.
Based on these findings, this website may pose potential risks to visitors.
Technical Description
The site uses a valid Let's Encrypt SSL certificate that was active at the time of the scan and is hosted on an Apache web server at IP address 186.64.119.45, associated with hosting in Curicó, Chile. The domain itself is relatively old, having been created in 2017, which may indicate that this is a compromised subdomain or repurposed hosting location rather than a newly registered standalone phishing domain.
DNSSEC status was not confirmed in the available data, and the protocol details were not provided. Although HTTPS is present, that alone should not be treated as a trust signal, since phishing pages commonly use valid certificates as well.
Share your experience with this website. Was it safe? Did you encounter any issues?