del-theccguy.netlify.app
Category: Malicious
To use full-featured product, you have to purchase a license for Combo Cleaner. Limited seven days free trial available. Combo Cleaner is owned and operated by RCS LT, the parent company of PCRisk.com.
Description of del-theccguy.netlify.app
This domain appears to host a webpage branded as "The Courier Guy," presenting itself as a parcel-delivery or shipping-payment interface. The visible content shows a multi-step shipment flow with sections such as order details, parcel dimensions, service, shipping fees, and payment details, suggesting that the page is intended to collect payment for a supposed delivery charge.
Based on the screenshot and page title, the site appears to imitate a courier-service workflow rather than operate as a general informational website. It is hosted on a Netlify subdomain rather than on a standalone brand-owned domain, which may indicate a temporary landing page or campaign-style deployment. The operator is not clearly identified in the provided data, and the page does not appear to provide the kind of corporate identity or trust information typically expected from a major logistics provider.
Safety Assessment for del-theccguy.netlify.app
Several security signals indicate elevated risk at the time of this scan. The domain was flagged by 7 out of 91 security engines, and multiple web-classification providers categorized it as phishing or fraud-related content. In addition, a major threat database listed the page for social-engineering activity, which is a strong indicator that the site may be attempting to mislead visitors into submitting payment or personal information.
The screenshot reinforces that concern: the page appears to request a small shipping payment while using courier branding and a delivery narrative that is commonly associated with payment-harvesting scams. Although the malware scan did not detect malicious files at the time of analysis, a clean file scan does not rule out phishing, since phishing pages often rely on deceptive forms and branding rather than malware payloads.
There is also a secondary reputation concern because the domain's IP address is listed on one mail-reputation blocklist, though that signal is weaker than the phishing detections and may reflect broader hosting or email-reputation issues rather than website content alone. Based on these findings, this website may pose potential risks to visitors.
Technical Description
The site is served over HTTPS with a valid certificate issued by DigiCert, expiring in March 2027. It appears to be hosted on Netlify infrastructure backed by AWS EC2 in Frankfurt, Germany, using the IP address 35.157.26.135. The domain uses Netlify-related hosting patterns and includes common third-party tracking and analytics resources.
DNSSEC appears to be unsigned, which is not uncommon but does mean DNS responses do not benefit from that additional integrity layer. No malicious files were flagged in the provided file scan, but the broader detection pattern suggests the primary concern may be deceptive page content and credential or payment harvesting rather than exploit delivery.
Share your experience with this website. Was it safe? Did you encounter any issues?