chipweb-voyage.com.br
Category: Phishing
To use full-featured product, you have to purchase a license for Combo Cleaner. Limited seven days free trial available. Combo Cleaner is owned and operated by RCS LT, the parent company of PCRisk.com.
Description of chipweb-voyage.com.br
chipweb-voyage.com.br appears to be a Brazilian web application branded as "ChipWeb-VoyAGE." Based on the page title, login screen, and visible Portuguese text, it appears to function as a management system (ERP) for travel agencies and tour operators. The homepage shown in the scan is not a public marketing site, but rather a credential-entry portal with fields for company registration number, username, and password, along with demo and help options.
The domain name combines "chipweb" and "voyage," which suggests a travel-technology or agency-management platform. The page design and labels indicate business software rather than a consumer travel-booking portal. Ownership details are limited in the scan data, so the operator cannot be independently confirmed from the available information alone.
Safety Assessment for chipweb-voyage.com.br
This domain presents mixed signals at the time of the scan. On one hand, 5 out of 91 security engines flagged it, with several classifying it as phishing or otherwise suspicious. Multiple web-classification sources also disagreed on the nature of the site, with some describing it as travel or business-related while others associated it with phishing. Because the visible page is a login portal that requests credentials, these detections merit caution, especially for users who did not intentionally navigate to this service.
On the other hand, the domain is not newly registered; it has been active for about 9 years, uses a valid SSL certificate, and major content-malice blacklist checks were reported as clean at the time of this scan. The malware scan did not report flagged files, although it did attach a generic malicious-object label to the domain and several internal resources. That kind of generic heuristic can be lower confidence on its own, but here it appears alongside multi-engine phishing detections, which increases concern. One blacklist-style source also listed the domain, so it would not be accurate to describe all reputation checks as fully clean.
Based on these findings, this website may pose potential risks to visitors at the time of this scan, particularly because it is a credential-collection page and several security engines flagged it as phishing-related.
Technical Description
The site was reachable over HTTPS with a valid Let's Encrypt certificate expiring in late 2026. It resolves to an IP hosted on Oracle Cloud Infrastructure in São Paulo, Brazil, and the web server identified itself as Apache/2.4.41 on Ubuntu. Nameservers are delegated to Oracle Cloud DNS, which is consistent with cloud-hosted deployment. DNSSEC status was not confirmed in the scan data.
From a security-review perspective, the infrastructure looks like a standard cloud-hosted web application rather than a parked or inactive domain. However, the page appears to expose a login interface directly, and the scan data shows several internal assets and URLs marked with a generic malicious heuristic. The JavaScript library list also includes an older jQuery 1.7.2 file, which may indicate outdated frontend components, though version age alone does not confirm compromise.
Share your experience with this website. Was it safe? Did you encounter any issues?