dahl[.]su
Category: Malicious Web Sites
To use full-featured product, you have to purchase a license for Combo Cleaner. Limited seven days free trial available. Combo Cleaner is owned and operated by RCS LT, the parent company of PCRisk.com.
Description of dahl[.]su
The domain dahl[.]su appears to host a simple landing or redirect-style page branded as "x.telega.me." Based on the page title, screenshot, and linked destinations, the site seems intended to route visitors toward a main site or mobile app distribution pages, including links to Apple App Store, Google Play, RuStore, and a Telegram-related destination. The visual design is minimal and centered around a "secure transition" message in Russian, suggesting it functions more as a gateway page than a full content website.
The site appears to be built with Tilda-hosted assets and served through an nginx web server. Ownership details are limited in the provided data, and the registrar is not disclosed here. The domain itself is relatively new, has no meaningful popularity ranking, and does not present the kind of organizational identity, company information, or detailed content that would normally help establish legitimacy for visitors evaluating an unfamiliar web property.
Safety Assessment for dahl[.]su
Several independent security signals raise concerns about this domain at the time of the scan. It was categorized by multiple web-classification providers as malicious, spyware/malware, or malicious web content, and 14 out of 92 security engines flagged it for malicious, phishing, malware, or suspicious activity. That level of multi-engine detection is a stronger warning sign than a single heuristic alert, especially when the domain is also very new and lacks an established traffic profile.
At the same time, the page-level malware crawl did not identify flagged files, and the checked blacklist databases in this dataset were reported as clean at the time of the scan. That mixed picture can occur when a site acts as a redirector, lure page, or campaign entry point rather than directly serving obvious malicious files. The screenshot's "secure transition" wording should not be treated as proof of legitimacy on its own, particularly when broader scan consensus is unfavorable.
Based on these findings, this website may pose potential risks to visitors.
Technical Description
The site was reachable over HTTPS with a valid Let's Encrypt certificate that, at the time of the scan, was set to expire on 2026-07-21. It is hosted on IP address 81.26.183.223, appears to use nginx, and is associated with hosting in Murmansk, Russia through OOO ComLine. Nameservers point to ns1.mcs.mail.ru and ns2.mcs.mail.ru. DNSSEC status is listed as unknown.
From a technical standpoint, the page appears lightweight and relies on static assets associated with the Tilda site-building platform. No malicious files or flagged outbound links were identified by the page crawl itself, but the domain's young age, lack of ranking, limited ownership transparency, and substantial multi-engine detection count are notable risk indicators at the infrastructure and reputation level.
Share your experience with this website. Was it safe? Did you encounter any issues?