auspost.customerserviceqr.com
Category: Phishing
To use full-featured product, you have to purchase a license for Combo Cleaner. Limited seven days free trial available. Combo Cleaner is owned and operated by RCS LT, the parent company of PCRisk.com.
Description of auspost.customerserviceqr.com
The domain auspost.customerserviceqr.com appears to be a subdomain hosted under customerserviceqr.com and is likely intended to present a customer-service or QR-code-related page. Based on the subdomain label "auspost," it may be attempting to reference Australia Post or postal-service-related communications, such as parcel tracking, delivery notices, or account verification prompts.
Available classification data associates this domain with phishing and fraud-related categories from multiple web-classification providers, although one provider labeled it more generically as technology. The domain itself is very new and does not appear to have an established traffic presence, which may indicate a short-lived campaign page rather than a long-standing public website.
Safety Assessment for auspost.customerserviceqr.com
This domain shows multiple high-risk indicators at the time of this scan. It was flagged by 21 out of 91 security engines, and several web-classification sources categorized it as phishing, fraud, spyware, or malware-related. In addition, one threat database listing was present, while other blacklist and browsing-safety checks were clean. The domain is also only 3 days old, which is a common pattern for disposable phishing infrastructure.
The hostname closely resembles Australia Post branding through the use of the "auspost" label, yet it is hosted on the unrelated parent domain customerserviceqr.com. That resemblance may indicate a look-alike setup intended to gain user trust. Although the file-based malware scan did not detect malicious code in the sampled content, phishing pages often rely on deceptive forms and branding rather than downloadable malware.
Based on these findings, this website may pose potential risks to visitors.
Technical Description
The site presented a valid Let's Encrypt SSL certificate expiring on 2026-09-15, which indicates encrypted HTTPS was configured at the time of testing. However, HTTPS alone does not validate legitimacy. DNSSEC appears to be unsigned, and the domain was registered very recently through Dominet (HK) Limited with nameservers at ALIDNS.
The server resolved to IP address 47.79.39.190, with hosting attributed to infrastructure associated with Zenlayer and related network providers in Tokyo, Japan. The web server identified itself as "workerman." No DNS-based mail-reputation blocklist hits were reported in this scan, but the combination of very recent registration, unsigned DNSSEC, and strong multi-engine phishing detections raises technical concern.
Share your experience with this website. Was it safe? Did you encounter any issues?