ch136645.tw1.ru
Category: Phishing
To use full-featured product, you have to purchase a license for Combo Cleaner. Limited seven days free trial available. Combo Cleaner is owned and operated by RCS LT, the parent company of PCRisk.com.
Description of ch136645.tw1.ru
This domain appears to host a French-language login page branded as "AR24," with messaging about confidentiality, data protection, and access to an electronic registered letter or attached documents. The page title and screenshot suggest it is presenting itself as a document-delivery or secure correspondence portal rather than a general informational website.
The domain name itself, ch136645.tw1.ru, does not appear to match the AR24 branding shown on the page. The page also references an external image from a separate domain containing "courier" and "compte-clients," which may indicate an attempt to imitate a customer-access portal for delivery or registered-mail services. Based on the available categories and page content, the site appears to be associated with credential collection under the guise of a legal or professional communications service.
Although the domain is old, the visible content does not resemble a primary corporate website and instead appears to be a narrowly focused sign-in page. That pattern is commonly seen on temporary campaign pages or cloned login portals.
Safety Assessment for ch136645.tw1.ru
Multiple independent security signals raise concern about this domain at the time of this scan. It was flagged by 19 out of 91 security engines, with many of those detections classifying it as phishing or fraud-related. In addition, one threat database listing was present, and the page screenshot shows a branded login-style interface asking users to continue in order to access a message or attachment, which is a pattern often associated with credential-harvesting pages.
There are also contextual warning signs beyond the engine detections. The domain name does not appear to align with the AR24 branding displayed on the page, which may indicate the site is impersonating or mimicking another service. The domain's IP address is also listed on one mail-reputation blocklist; this is a weaker signal than direct phishing detections, but it still adds some caution. While one malware scan reported no directly flagged files and only generic suspicious-object heuristics, that cleaner result is outweighed here by the broader multi-engine phishing consensus and the page's login-lure presentation.
Based on these findings, this website may pose potential risks to visitors.
Technical Description
The site was reachable over HTTPS with a valid TLS certificate issued by a mainstream certificate authority, expiring in March 2027. It is hosted on IP address 92.53.96.169, served by nginx/1.30.4, and appears to be hosted by JSC "TIMEWEB" in St Petersburg, Russia. The domain uses nameservers associated with the same hosting provider.
The domain itself is relatively old, having been created in 2006, which can sometimes lend legitimacy, but age alone does not offset phishing indicators when a subdomain or hosted page appears to be abused. DNSSEC status was reported as unknown. No iframe activity was observed in the supplied scan data, but several internal resource URLs were marked with generic suspicious heuristics.
Share your experience with this website. Was it safe? Did you encounter any issues?