accounts-fe50ccd9.jkhjkjk.workers.dev
Category: Phishing
To use full-featured product, you have to purchase a license for Combo Cleaner. Limited seven days free trial available. Combo Cleaner is owned and operated by RCS LT, the parent company of PCRisk.com.
Description of accounts-fe50ccd9.jkhjkjk.workers.dev
This domain appears to host a lightweight web page on the Cloudflare Workers platform rather than a full standalone business website. Based on the page title, the screenshot, and the visible form fields, it presents itself as an "Excel - Shared Document" login page that asks visitors to enter an email address and password before downloading or viewing a shared file.
The domain name itself does not appear to match a recognizable organization or official Microsoft-owned property, and the page content suggests it may be attempting to imitate a document-sharing or Office-related login experience. The available data does not identify a legitimate operator, publisher, or business entity behind the page.
Safety Assessment for accounts-fe50ccd9.jkhjkjk.workers.dev
Several independent security signals indicate elevated risk at the time of this scan. The domain was flagged by 8 out of 91 security engines, and multiple web-classification providers categorized it as phishing or fraud-related content. In addition, the screenshot shows a credential-entry form styled to resemble an Office/Excel document prompt, which may be consistent with attempts to collect email login details under the guise of accessing a shared file.
The malware scan did not detect malicious files, and major content-focused threat databases listed here did not report an active malware or phishing listing at the time of this scan. However, that does not outweigh the broader phishing-related classifications, the deceptive-looking login presentation, and the fact that the domain's IP address is listed on one mail-reputation blocklist, which is a weaker but still cautionary signal.
Taken together, the available evidence suggests this page may be intended to impersonate a document-sharing login flow in order to capture credentials. Based on these findings, this website may pose potential risks to visitors.
Technical Description
The site is served over HTTPS with a valid Let's Encrypt certificate and is hosted behind Cloudflare infrastructure on a Cloudflare-owned IP address in Canada. The domain uses Cloudflare nameservers and appears to be deployed via the workers.dev platform, which is commonly used for serverless web applications and temporary web content.
DNSSEC appears to be unsigned, and the scan did not identify malicious files, external links, or iframe activity on the captured page. Even so, the technical setup is relatively minimal and the page content itself raises concern, because phishing pages often use reputable hosting/CDN services and valid TLS certificates to appear more convincing.
Share your experience with this website. Was it safe? Did you encounter any issues?