2a5c49.icefactory.cl
Category: Phishing
To use full-featured product, you have to purchase a license for Combo Cleaner. Limited seven days free trial available. Combo Cleaner is owned and operated by RCS LT, the parent company of PCRisk.com.
Quttera Web Malware Removal is a paid subscription service. Pricing, plans, and trial availability are set by Quttera. Quttera is operated by Quttera Ltd, an independent third-party company unrelated to RCS LT. PCrisk.com may earn a referral commission when users sign up through this link.
Description of 2a5c49.icefactory.cl
This domain is a subdomain under icefactory.cl, but the specific host name "2a5c49" appears machine-generated rather than branded or user-facing. Based on the page title and screenshot, the page presents itself as an "Adobe Acrobat Reader" secure PDF access portal and prompts visitors to enter an email address before continuing to a document.
The content does not appear to represent a normal corporate website, product homepage, or public document service. Instead, it appears to be a single-purpose landing page designed to imitate a document-sharing or PDF access workflow, likely to persuade users to submit credentials or other identifying information.
There is no visible evidence on the page of a legitimate operator identity, company details, support information, or standard website navigation. Based on the available content and presentation, this host appears to be set up primarily as a credential-harvesting or deceptive document-access page rather than a full business website.
Safety Assessment for 2a5c49.icefactory.cl
Multiple scan signals indicate elevated risk at the time of this scan. The domain was flagged by 17 out of 91 security engines, with many of those detections classifying it as phishing or malicious. In addition, the page screenshot shows an email-entry form styled as an Adobe Acrobat document-access screen, which may be intended to mimic a trusted brand and collect user information under false pretenses.
Blacklist and reputation data were mixed rather than fully clean. Major content-malice databases in the provided data did not report a listing at the time of the scan, but the domain's IP address was listed on one mail-reputation blocklist. That type of listing is a weaker signal than direct phishing or malware listings, yet it still adds some caution. A malware scan also produced a suspicious result on one scanned page, although without a named malware family.
The host is also unranked in traffic data and uses a random-looking subdomain label, both of which can be consistent with short-lived phishing infrastructure. Based on these findings, this website may pose potential risks to visitors.
Technical Description
The site was reachable over HTTPS with a valid Let's Encrypt certificate that, at the time of the scan, was set to expire on 2026-11-08. It was hosted on IP address 186.64.119.45 in Curicó, Chile, with Apache reported as the web server and hosting attributed to ZAM LTDA. DNSSEC status was not available in the provided data.
From an infrastructure perspective, the use of TLS means traffic may be encrypted in transit, but that does not by itself indicate legitimacy. The combination of a long-lived parent domain, a random-looking subdomain, an Apache-hosted single-page credential prompt, and one mail-reputation blocklist hit may indicate that a compromised or repurposed host is being used for deceptive content.
Share your experience with this website. Was it safe? Did you encounter any issues?