allegro.pryi40-23gf2.casa
Category: Phishing
To use full-featured product, you have to purchase a license for Combo Cleaner. Limited seven days free trial available. Combo Cleaner is owned and operated by RCS LT, the parent company of PCRisk.com.
Description of allegro.pryi40-23gf2.casa
This domain appears to be a newly created subdomain under the .casa top-level domain, using the label "allegro" followed by a random-looking hostname segment. Based on the visible page content, the site does not appear to present a normal business homepage or a clearly identified service. The screenshot shows a mostly blank page with a short Chinese message, which suggests either a placeholder, a minimal landing page, or a page that may only display specific content under certain conditions.
No clear operator identity, company information, or legitimate site purpose is visible from the available data. The domain structure and lack of branding or descriptive metadata make it difficult to associate the site with an established organization. Based on the domain pattern and scan context, it appears more consistent with a disposable or campaign-specific web endpoint than with a mature public-facing website.
Safety Assessment for allegro.pryi40-23gf2.casa
Multiple security signals indicate elevated risk at the time of this scan. The domain was flagged by 13 out of 90 security engines, with most detections describing phishing-related activity and one indicating malware-related concerns. In addition, one major phishing database listed the domain, and the domain's IP address is listed on one mail-reputation blocklist. Although the malware file scan did not detect malicious files in the limited content that was scanned, that does not outweigh the broader reputation-based findings.
The domain is also only 2 days old, has no established traffic ranking, and presents very little visible content. Those factors are commonly associated with short-lived phishing infrastructure, especially when combined with a random-looking hostname pattern and multi-engine phishing detections. The page does use valid HTTPS, but a valid certificate only confirms encrypted transport and does not by itself indicate legitimacy.
Based on these findings, this website may pose potential risks to visitors.
Technical Description
The site is served through Cloudflare infrastructure and resolves to an IP address associated with that network in Toronto, Canada. It presents a valid SSL/TLS certificate issued by Google Trust Services, with expiry listed as 2026-11-30. DNSSEC appears to be unsigned, which is not uncommon but does mean DNS responses do not benefit from DNSSEC validation.
From a security posture perspective, the main concerns are not the certificate or CDN usage but the surrounding reputation signals: the domain is extremely new, hosted behind shared edge infrastructure, and associated with multiple phishing detections. The page itself appears minimal, and no meaningful external links, referenced domains, or iframes were observed in the scan data.
Share your experience with this website. Was it safe? Did you encounter any issues?