def8a2.icefactory.cl
Category: Malicious
To use full-featured product, you have to purchase a license for Combo Cleaner. Limited seven days free trial available. Combo Cleaner is owned and operated by RCS LT, the parent company of PCRisk.com.
Quttera Web Malware Removal is a paid subscription service. Pricing, plans, and trial availability are set by Quttera. Quttera is operated by Quttera Ltd, an independent third-party company unrelated to RCS LT. PCrisk.com may earn a referral commission when users sign up through this link.
Description of def8a2.icefactory.cl
The domain def8a2.icefactory.cl appears to be a subdomain hosted under icefactory.cl, but the scanned page itself does not present a normal corporate or informational website. Based on the page title and screenshot, it appears to display a document-themed landing page branded as "Adobe Acrobat Reader" and prompts visitors to enter an email address to continue to a supposedly secure PDF document.
This kind of page layout is commonly associated with credential-harvesting or document-access lures rather than a legitimate Adobe-operated service. The domain naming pattern is also unusual for a public-facing document portal, using a random-looking subdomain and path structure instead of a recognizable branded service address. Based on the available content and classifications, the site appears to be functioning as a phishing-style document access page rather than a standard technology or business website.
Safety Assessment for def8a2.icefactory.cl
Multiple scan signals indicate elevated risk at the time of this scan. The domain was flagged by 14 out of 91 security engines, and several web-classification providers categorized it as phishing, fraud, malware, or other malicious activity. In addition, the screenshot shows a page imitating an Adobe document-access workflow and requesting an email address before allowing access to a supposed PDF, which is a pattern often associated with credential collection.
The malware scan also reported one suspicious flagged file, although that result on its own would be lower confidence without corroboration. More importantly, the broader consensus across security engines and the visible page content point to a likely phishing setup. While major content-malice blocklists listed in the scan were clean at the time, the domain's IP address was listed on one mail-reputation blocklist, which adds a minor supporting caution rather than serving as primary evidence.
Based on these findings, this website may pose potential risks to visitors.
Technical Description
The site was reachable over HTTPS with a valid Let's Encrypt certificate that was set to expire on 2026-11-08. A valid certificate only indicates encrypted transport and should not be treated as proof of legitimacy. The server appears to run Apache and resolves to IP address 186.64.119.45, hosted by ZAM LTDA in Curicó, Chile.
WHOIS data indicates the domain has existed for about six years, although registrar, nameserver, protocol, and DNSSEC details were not available in the provided scan. No external links or iframes were observed in the scanned page, which suggests a relatively simple landing page. The main technical concern is not the TLS setup, but the combination of suspicious page behavior, unusual subdomain structure, and multi-engine phishing detections.
Share your experience with this website. Was it safe? Did you encounter any issues?