elliallawson-drive-secure-pdf.surge[.]sh
Category: Information Technology, Malicious
To use full-featured product, you have to purchase a license for Combo Cleaner. Limited seven days free trial available. Combo Cleaner is owned and operated by RCS LT, the parent company of PCRisk.com.
Description of elliallawson-drive-secure-pdf.surge[.]sh
This domain appears to be a page hosted on Surge, a static web hosting platform, rather than an official file-sharing property. The subdomain name includes terms such as "drive," "secure," and "pdf," and the page title shown in the scan is "Shared files - Google Drive." The screenshot presents a file-listing interface styled to resemble a cloud document-sharing page, with several PDF documents displayed as if they were shared business files.
Based on the domain structure and visible content, the page appears intended to imitate a document delivery or file-sharing experience rather than represent a standalone business or publisher. It does not appear to be operated from an official Google-owned domain, and the use of a third-party hosting subdomain for a page visually resembling a major cloud service may indicate an attempt to attract clicks from users expecting a legitimate shared-document portal.
Safety Assessment for elliallawson-drive-secure-pdf.surge[.]sh
Multiple security signals indicate elevated risk at the time of this scan. The URL was flagged by 12 out of 92 security engines, and several web-classification sources categorized it as phishing or fraud-related. The screenshot also shows a page designed to resemble a well-known cloud storage service while being hosted on an unrelated surge.sh subdomain, which may be consistent with credential harvesting or deceptive document-lure activity.
At the same time, some point-in-time checks were clean: the malware file scan did not identify flagged files, and major blacklist and threat-database checks included in this scan did not report listings. However, a clean file scan does not outweigh the broader phishing consensus when the page presentation appears to mimic a trusted brand on a non-official domain.
Based on these findings, this website may pose potential risks to visitors. Users should be cautious about entering credentials, downloading files, or interacting with prompts on this page.
Technical Description
The site was served over HTTPS with a valid TLS certificate issued by Sectigo, hosted on DigitalOcean infrastructure in Amsterdam, and fronted by the Surge web server/platform. The domain itself is relatively old, but this is a subdomain on a shared hosting service, so the age of the parent domain does not necessarily indicate trustworthiness for this specific page.
DNSSEC appears to be unsigned, and the page is using Surge nameservers. No malicious files or flagged external links were identified in the limited scan data, but the main technical concern is the apparent brand-mimicking presentation on third-party hosting rather than malware delivery. That pattern may be associated with phishing campaigns even when infrastructure and TLS appear otherwise normal.
Share your experience with this website. Was it safe? Did you encounter any issues?