auth2usngwd0c88bdrvsharepoint.wardhealthpa.com
Category: Phishing
To use full-featured product, you have to purchase a license for Combo Cleaner. Limited seven days free trial available. Combo Cleaner is owned and operated by RCS LT, the parent company of PCRisk.com.
Description of auth2usngwd0c88bdrvsharepoint.wardhealthpa.com
This domain appears to be a highly specific subdomain under wardhealthpa.com, using terms such as "auth," "sharepoint," and a long random-looking string that resembles a login or document-access endpoint. Based on the naming pattern and the screenshot, it appears to be presenting a page associated with account access or file-sharing, likely attempting to resemble a Microsoft SharePoint or Microsoft 365 workflow.
The visible page content is limited by a verification interstitial, but the blurred background appears to imitate a business or document-management interface. There is no clear evidence that this subdomain represents an official standalone service operated by a recognized software vendor; instead, it appears to be a custom-hosted page on a recently created subdomain and domain infrastructure. That combination can be consistent with temporary credential-harvesting or impersonation setups, especially when enterprise login branding is referenced in the hostname.
Safety Assessment for auth2usngwd0c88bdrvsharepoint.wardhealthpa.com
This domain shows multiple high-risk indicators at the time of this scan. It was flagged by 20 out of 91 security engines, with the detections largely describing phishing-related activity. In addition, the domain is only 6 days old, has no established traffic ranking, and uses a hostname structure designed to resemble authentication and SharePoint-related access, which may increase the likelihood of user confusion.
The screenshot shows a verification or access-check page in front of what appears to be a blurred business-style interface, a pattern sometimes used to delay analysis or add legitimacy to a deceptive login flow. Although blacklist databases included in this scan did not show broad listings and the malware file scan did not detect malicious files, those signals do not outweigh the multi-engine phishing consensus and the very recent registration.
Based on these findings, this website may pose potential risks to visitors.
Technical Description
The site presented a valid Let's Encrypt SSL certificate expiring on 2026-08-30, which indicates encrypted transport was available at the time of testing. It resolves to 172.86.91.9, hosted by FranTech Solutions in Dallas, United States, and the web server identified itself as Apache/2.4.58 on Ubuntu. The domain uses Microsoft-related nameservers, while DNSSEC appears to be unsigned.
From a security posture perspective, the main concerns are not certificate validity but the surrounding context: a very new domain, unsigned DNSSEC, no meaningful reputation history, and a login-themed subdomain pattern that appears crafted to mimic enterprise authentication or SharePoint access. The screenshot also indicates a verification challenge page, which can limit direct inspection and may be used by both legitimate and deceptive sites.
Share your experience with this website. Was it safe? Did you encounter any issues?