2b6812.icefactory.cl
Category: Malicious
To use full-featured product, you have to purchase a license for Combo Cleaner. Limited seven days free trial available. Combo Cleaner is owned and operated by RCS LT, the parent company of PCRisk.com.
Quttera Web Malware Removal is a paid subscription service. Pricing, plans, and trial availability are set by Quttera. Quttera is operated by Quttera Ltd, an independent third-party company unrelated to RCS LT. PCrisk.com may earn a referral commission when users sign up through this link.
Description of 2b6812.icefactory.cl
This subdomain appears to host a web page styled as a document-access portal, using the title "Adobe Acrobat - Secure PDF Document" and presenting an email-entry form to continue to a supposed PDF. Based on the screenshot and metadata, the page is designed to resemble a secure document-sharing or document-login experience rather than a general informational website.
The domain is a subdomain of icefactory.cl, a Chilean domain that has existed for several years, but the specific hostname shown here uses a random-looking label and does not present clear branding or organizational identification. That combination may indicate a temporary or campaign-specific page rather than an established standalone service.
The visible content suggests the page's purpose may be to collect visitor email addresses or credentials under the pretense of granting access to a protected document. The use of Adobe-themed wording on an unrelated subdomain also raises questions about whether the page is attempting to imitate a trusted document platform.
Safety Assessment for 2b6812.icefactory.cl
Multiple security signals indicate elevated risk at the time of this scan. The URL was flagged by 17 out of 91 security engines, and several web-classification providers categorized it as phishing or fraud-related. The screenshot also shows a document-themed login prompt asking for an email address before allowing access to a supposed PDF, which is a common pattern associated with credential-harvesting pages.
Blacklist and reputation data were mixed rather than uniformly clean. Major content-focused threat databases in the provided data did not report a listing at the time of the scan, but the domain's IP address was listed on one mail-reputation blocklist. That DNS-based listing is a weaker signal than direct phishing detections, yet it still adds a small amount of caution to the overall picture.
Although the parent domain is several years old and the site uses valid HTTPS, those factors do not outweigh the combination of multi-engine phishing detections, phishing-related categorization, and the deceptive-looking Adobe-themed login page. Based on these findings, this website may pose potential risks to visitors.
Technical Description
The site was reachable over HTTPS with a valid Let's Encrypt certificate expiring in November 2026. It appears to be served by Apache from IP address 186.64.119.45, hosted by ZAM LTDA in Curicó, Chile. DNSSEC status was reported as unknown, and the domain uses nameservers under pymedns.net.
From a technical risk perspective, the most notable concern is not the TLS setup but the application-layer behavior: a random-looking subdomain and path structure, minimal visible site content, and a form-driven document-access page that appears inconsistent with the claimed Adobe branding. One scanned file was also marked suspicious by a malware scan, though without a named malware family, so that specific file-level signal should be treated as lower confidence than the broader phishing detections.
Share your experience with this website. Was it safe? Did you encounter any issues?