9b13de.icefactory.cl
Category: Phishing
To use full-featured product, you have to purchase a license for Combo Cleaner. Limited seven days free trial available. Combo Cleaner is owned and operated by RCS LT, the parent company of PCRisk.com.
Quttera Web Malware Removal is a paid subscription service. Pricing, plans, and trial availability are set by Quttera. Quttera is operated by Quttera Ltd, an independent third-party company unrelated to RCS LT. PCrisk.com may earn a referral commission when users sign up through this link.
Description of 9b13de.icefactory.cl
This subdomain appears to host a single-purpose web page presented as an "Adobe Acrobat" or "Adobe Acrobat Reader" secure PDF access screen. Based on the page title and screenshot, the page claims to provide access to a protected PDF document and prompts visitors to enter an email address before continuing. The content does not resemble a full corporate website for the underlying icefactory.cl domain; instead, it appears to be a narrowly targeted landing page on a random-looking subdomain and path.
Safety Assessment for 9b13de.icefactory.cl
Several scan signals indicate elevated risk at the time of this scan. The URL was flagged by 16 out of 91 security engines, with many classifying it as phishing or malicious, and the page screenshot shows branding associated with Adobe while requesting an email address to access a supposed secure document. That combination is commonly associated with credential-harvesting pages that imitate document-sharing or login workflows. The random-looking subdomain and long path also add to the concern, as they do not appear consistent with a normal branded document portal.
Additional checks were mixed rather than uniformly clean. A malware scan marked one scanned page as suspicious, although without a named malware family, and the domain's IP address is listed on one mail-reputation blocklist, which is a weaker signal than direct phishing detections but still worth noting. While some major threat databases were clean at the time of this scan, the multi-engine phishing consensus and the page's impersonation-style presentation are stronger indicators. Based on these findings, this website may pose potential risks to visitors.
Technical Description
The site was reachable over HTTPS with a valid Let's Encrypt certificate expiring on 2026-11-08. It appears to be served by Apache from IP address 186.64.119.45 and hosted by ZAM LTDA in Curicó, Chile. The parent domain is not newly registered, with a creation date in 2017, but this does not by itself reduce concern for a suspicious subdomain because older domains can still host compromised or abusive content.
DNSSEC status was reported as unknown. No external links, referenced domains, or iframes were identified in the supplied scan data, suggesting a relatively simple page structure. The main technical concern is not the TLS setup itself, but the use of a random-looking subdomain and path to present a branded document-access form that may be intended to collect user information.
Share your experience with this website. Was it safe? Did you encounter any issues?