bgta-cy3si.sevalla.page
Category: Phishing, Spam
To use full-featured product, you have to purchase a license for Combo Cleaner. Limited seven days free trial available. Combo Cleaner is owned and operated by RCS LT, the parent company of PCRisk.com.
Description of bgta-cy3si.sevalla.page
The domain bgta-cy3si.sevalla.page appears to host a Spanish-language payment page titled "Pago PSE Seguro." Based on the screenshot, it presents itself as a secure checkout flow for a "Plan Empresarial Premium" priced in Colombian pesos and asks the visitor to select a bank to continue with a PSE payment. The page also displays Microsoft Office 365 branding, which suggests it may be attempting to associate itself with a well-known productivity service while collecting payment-related input from users.
The domain itself does not appear to match an official Microsoft or established payment-provider domain. It uses a subdomain under sevalla.page rather than a recognizable corporate payment hostname, and the site is not ranked among widely visited domains. Based on the available content and classifications, this page appears to function as a payment-themed landing page that may be intended to solicit banking interaction under the guise of a trusted brand or service.
Safety Assessment for bgta-cy3si.sevalla.page
Multiple security signals indicate elevated risk at the time of this scan. The domain was flagged by 9 out of 92 security engines, with several classifying it as phishing or otherwise malicious, and web-classification sources also labeled it as phishing and spam. In addition, the screenshot shows a payment interface using Microsoft Office 365 branding on a non-official-looking domain, which may indicate an attempt to imitate a trusted service and encourage users to submit sensitive financial information.
At the same time, some point-in-time checks were clean: the malware scan did not identify flagged files, and the checked blacklist databases did not report listings at the time of review. Those clean results do not outweigh the multi-engine phishing consensus and the suspicious branding/payment presentation. Based on these findings, this website may pose potential risks to visitors.
Technical Description
The site was reachable over HTTPS with a valid TLS certificate issued by Google Trust Services, fronted by Cloudflare infrastructure, and resolving to an IP associated with Cloudflare in Toronto, Canada. The domain uses Cloudflare nameservers and has DNSSEC listed as unsigned. The certificate validity and CDN usage may help with transport security and availability, but they do not by themselves establish legitimacy.
From an infrastructure perspective, the domain is about two years old and registered through a major registrar, which can sometimes make a site appear more established. However, the lack of DNSSEC, the use of a generic-looking subdomain, the absence of broad popularity signals, and the phishing-related detections are notable concerns at the time of this scan.
Share your experience with this website. Was it safe? Did you encounter any issues?