comepay-vip-members.netlify.app
Category: Phishing
To use full-featured product, you have to purchase a license for Combo Cleaner. Limited seven days free trial available. Combo Cleaner is owned and operated by RCS LT, the parent company of PCRisk.com.
Description of comepay-vip-members.netlify.app
This domain appears to host a login page branded as "COMEPAY" and presented as a member or account-access portal. The visible interface asks for a phone number, password, and a 6-digit PIN, which suggests it is intended to collect account credentials for a payment-related or wallet-related service.
Based on the subdomain structure, the page is hosted on Netlify rather than on a dedicated branded domain. The available page metadata is minimal, and the screenshot shows a very simple sign-in form with limited supporting company information, no clear operator identity, and no visible business details beyond the COMEPAY name.
Because the site appears to focus on account access rather than general informational content, it would most likely fit within a finance-related or account-portal context. However, based on the available data, the operator and legitimacy of the service are not clearly established from the page itself.
Safety Assessment for comepay-vip-members.netlify.app
Multiple security signals indicate elevated risk at the time of this scan. The domain was flagged by 15 out of 91 security engines, with the detections broadly classifying it as phishing or otherwise malicious. In addition, the screenshot shows a credential-collection form requesting a phone number, password, and 6-digit PIN, which is consistent with the kind of data-entry page commonly used in account-harvesting campaigns.
Although the malware scan did not identify malicious files and several major threat databases did not list the URL at the time of review, the domain's IP address was listed on one mail-reputation blocklist. That signal alone would be weak, but in this case it appears alongside substantial multi-engine phishing detections and a low-trust presentation hosted on a generic subdomain rather than a clearly established official brand domain.
The domain is older than many throwaway phishing pages, but age by itself does not outweigh the concentration of phishing detections and the page's credential-focused design. Based on these findings, this website may pose potential risks to visitors.
Technical Description
The site uses a valid SSL/TLS certificate issued by DigiCert, and it is hosted on Netlify infrastructure backed by AWS EC2 in Frankfurt, Germany. A valid certificate helps encrypt traffic in transit, but it does not by itself verify that the underlying service is trustworthy. The domain uses Netlify's hosting environment and Name.com as registrar.
DNSSEC appears to be unsigned, which means DNS responses may not benefit from that additional integrity layer. No malicious files or flagged external links were identified in the limited file scan provided, but the combination of a hosted subdomain, minimal page content, and strong phishing detections from multiple security engines remains a notable concern.
Share your experience with this website. Was it safe? Did you encounter any issues?