detsysscanner.com
Category: Phishing
To use full-featured product, you have to purchase a license for Combo Cleaner. Limited seven days free trial available. Combo Cleaner is owned and operated by RCS LT, the parent company of PCRisk.com.
Description of detsysscanner.com
detsysscanner.com appears to present itself as an online browser and system diagnostic tool branded as "Microsoft SysScan." Based on the page title, metadata, and screenshot, the site claims to run in-browser checks for browser errors, outdated versions, insecure settings, and privacy issues without requiring downloads. The homepage uses a clean utility-style layout with a prominent "Start Scan" call to action and panels showing session and device information.
The domain name and on-page branding may raise questions because the site prominently references Microsoft while operating from a separate, recently registered domain that does not appear to be an official Microsoft web property based on the available data. The site appears to be positioned in the technology or system-utility space, but its branding and messaging suggest it may be attempting to benefit from user trust associated with a major software company.
Safety Assessment for detsysscanner.com
This domain shows several notable risk indicators at the time of this scan. It was flagged by 15 out of 91 security engines, with many of those detections classifying it as phishing or otherwise malicious. In addition, the domain is very new at only 16 days old and has no established traffic ranking, which can be consistent with short-lived deceptive campaigns. The page also prominently uses "Microsoft SysScan" branding on a non-official domain, which may indicate an attempt to resemble a trusted brand and could mislead visitors.
At the same time, the page-level malware scan did not identify flagged files during this specific check, and major content-malice blacklist databases included in the scan were clean. However, the domain's IP address is listed on one mail-reputation blocklist, which is a weaker signal on its own but still worth noting. Taken together, the stronger indicators here are the multi-engine phishing detections, the very recent registration, and the apparent brand-resembling presentation.
Based on these findings, this website may pose potential risks to visitors.
Technical Description
The site is served over HTTPS with a valid Let's Encrypt certificate that was active at the time of the scan. It appears to be hosted on an nginx web server at IP address 157.230.180.90, associated with DigitalOcean in North Bergen, United States. DNSSEC is not enabled, and the domain uses third-party nameservers from TopDNS.
From a technical standpoint, the infrastructure is fairly typical for a small or newly deployed site, but the combination of recent domain creation, unsigned DNSSEC status, and commodity cloud hosting provides limited trust signals by itself. No malicious files were identified in the limited file scan, though that does not outweigh the broader phishing-related detections from multiple security engines.
Share your experience with this website. Was it safe? Did you encounter any issues?