dui2yh5g50r9s.cloudfront.net
Category: Phishing
To use full-featured product, you have to purchase a license for Combo Cleaner. Limited seven days free trial available. Combo Cleaner is owned and operated by RCS LT, the parent company of PCRisk.com.
Description of dui2yh5g50r9s.cloudfront.net
This domain is a CloudFront-hosted web page presented as a French-language login portal under the label “AR24.” The page title is “Formulaire,” and the visible content asks visitors to enter email credentials, with branding icons referencing several email or service providers. Based on the screenshot, the page appears to function as a credential-entry form rather than a full corporate website, and it includes basic navigation, support, and legal footer links.
The hostname itself is a generated CloudFront subdomain rather than a branded primary domain, which suggests the page may be delivered through a content distribution setup instead of an organization’s main public website. While the underlying CloudFront domain has existed for many years as part of Amazon’s infrastructure, that age reflects the platform namespace rather than proving the legitimacy of the specific page content currently served from this subdomain.
Safety Assessment for dui2yh5g50r9s.cloudfront.net
This page shows several cautionary indicators at the time of this scan. One out of 91 security engines flagged the URL for phishing, and the screenshot depicts a generic login form requesting email and password details while displaying multiple third-party service logos. That combination may be consistent with credential-harvesting behavior, especially because the page is hosted on a non-branded CloudFront subdomain rather than an obvious official domain for the services shown.
At the same time, the broader malware scan did not identify malicious files, and major threat-database checks were clean at the time of this scan. No threats were detected in the small set of scanned files, external links were not flagged, and blacklist checks did not show listings in the checked content-malice databases. Even so, phishing pages often contain minimal code and may evade file-based malware detection, so a clean malware scan does not by itself remove the concern raised by the page’s design and credential prompt.
Based on these findings, this website may pose potential risks to visitors, particularly if asked to enter account credentials.
Technical Description
The site is served through AWS CloudFront and resolves to IP address 13.227.173.51, with hosting geolocated to Paris, France in this scan. It presents a valid SSL/TLS certificate issued for Amazon infrastructure, with expiry listed as 2026-09-09. The web server is identified as CloudFront, and the domain uses AWS nameservers.
DNSSEC appears to be unsigned. The hostname is an autogenerated CloudFront subdomain rather than a dedicated branded domain, which can be normal for temporary or distributed content but may also make ownership and authenticity less transparent to end users. No DNS-based blocklist hits were reported at the time of this scan.
Share your experience with this website. Was it safe? Did you encounter any issues?