27cd38.icefactory.cl
Category: Malicious
To use full-featured product, you have to purchase a license for Combo Cleaner. Limited seven days free trial available. Combo Cleaner is owned and operated by RCS LT, the parent company of PCRisk.com.
Quttera Web Malware Removal is a paid subscription service. Pricing, plans, and trial availability are set by Quttera. Quttera is operated by Quttera Ltd, an independent third-party company unrelated to RCS LT. PCrisk.com may earn a referral commission when users sign up through this link.
Description of 27cd38.icefactory.cl
This subdomain appears to host a single-purpose web page styled as an "Adobe Acrobat Reader" document-access portal. Based on the page title, screenshot, and form layout, it presents itself as a secure PDF viewing or document-delivery page and asks visitors to enter an email address before continuing.
The domain is a subdomain of icefactory.cl, a Chilean domain that has existed since 2017, but the specific hostname shown here uses a random-looking label rather than a clear business or product name. That naming pattern, combined with the minimal page content and document-themed branding, suggests this page may be intended for campaign-based use rather than as part of a normal public-facing website.
No clear operator identity, company details, or legitimate service information are visible in the provided metadata and screenshot. Based on the available content, the page appears to imitate a document-access workflow associated with a well-known software brand rather than presenting an independently branded service.
Safety Assessment for 27cd38.icefactory.cl
Multiple security signals indicate elevated risk at the time of this scan. The domain was flagged by 13 out of 91 security engines, and several web-classification sources categorized it as phishing or fraud-related. The screenshot also shows a document-themed login prompt using Adobe branding and requesting an email address to access a supposed secure PDF, which is a pattern commonly associated with credential-harvesting pages.
Additional scan context is mixed but still concerning. A malware scan marked one scanned path as suspicious, although that result appears to be heuristic rather than tied to a named malware family. Major content-malice blocklists included in the scan were clean at the time of review, but the domain's IP address was listed on one mail-reputation blocklist, which is a weaker signal on its own and does not by itself prove website abuse.
Taken together, the multi-engine phishing detections, phishing-related categorization, deceptive branding cues, and credential-collection behavior materially increase risk. Based on these findings, this website may pose potential risks to visitors.
Technical Description
The site uses a valid Let's Encrypt SSL certificate with an expiry date of 2026-11-08, which means traffic to the page can be encrypted in transit. It is hosted on IP address 186.64.119.45 in Curicó, Chile, with Apache reported as the web server and ZAM LTDA as the hosting provider. The domain uses nameservers under pymedns.net, while DNSSEC status is unknown.
From a technical perspective, the presence of HTTPS should not be treated as a trust signal by itself, since phishing pages also commonly use valid certificates. The hostname structure appears randomly generated, and the flagged suspicious path is unusually long and opaque, which may be consistent with disposable or campaign-specific infrastructure.
Share your experience with this website. Was it safe? Did you encounter any issues?