acessecasasbahia[.]com
Category: Phishing
To use full-featured product, you have to purchase a license for Combo Cleaner. Limited seven days free trial available. Combo Cleaner is owned and operated by RCS LT, the parent company of PCRisk.com.
Description of acessecasasbahia[.]com
The domain acessecasasbahia[.]com appears to present itself as a parcel or order-tracking page for Casas Bahia, a well-known Brazilian retail brand. The screenshot shows Casas Bahia branding, a Portuguese-language interface, and a form asking users to search for orders using CPF or order ID, suggesting that the page is intended to collect customer order-related information.
Based on the domain name and page layout, this site appears to be targeting Brazilian online shoppers looking to track deliveries or access account-related order details. However, the domain is not the brand's primary official domain shown in the page links, and it appears to function more like a branded landing page than a full retail storefront.
Safety Assessment for acessecasasbahia[.]com
This domain shows several risk indicators at the time of this scan. It was flagged by 1 out of 91 security engines, while other malware scanning results and blacklist checks did not detect threats. Even so, the domain name closely incorporates the Casas Bahia brand while using a separate .com address, and the page screenshot strongly imitates the retailer's visual identity. That combination may indicate a look-alike site intended to capture personal or order-related information.
Additional context increases concern: the domain age is 0 days, it is not ranked in major traffic lists, and the page asks for a Brazilian taxpayer identifier (CPF) or order ID. Newly created domains that mimic established brands and request sensitive identifiers may present elevated phishing risk, even when broad blacklist coverage is still limited. The presence of links to the legitimate retailer may also be consistent with an attempt to appear credible.
Based on these findings, this website may pose potential risks to visitors.
Technical Description
The site was observed using a valid Let's Encrypt SSL certificate and is hosted on Vercel infrastructure, with the server resolving to an IP in the United States. The certificate being valid helps confirm encrypted transport, but it does not by itself establish legitimacy. DNSSEC appears to be unsigned, and the domain uses Cloudflare nameservers.
From a scanning perspective, no malicious files, flagged external links, or iframe-based threats were detected at the time of this scan. However, the combination of very recent registration, brand-resembling domain naming, and a data-entry form requesting personal information is a notable concern from a technical trust standpoint.
Share your experience with this website. Was it safe? Did you encounter any issues?