hammerhead-app-ub55h.ondigitalocean.app
Category: Phishing And Fraud
To use full-featured product, you have to purchase a license for Combo Cleaner. Limited seven days free trial available. Combo Cleaner is owned and operated by RCS LT, the parent company of PCRisk.com.
Quttera Web Malware Removal is a paid subscription service. Pricing, plans, and trial availability are set by Quttera. Quttera is operated by Quttera Ltd, an independent third-party company unrelated to RCS LT. PCrisk.com may earn a referral commission when users sign up through this link.
Description of hammerhead-app-ub55h.ondigitalocean.app
This domain appears to be a hosted web application running on a shared cloud subdomain under ondigitalocean.app rather than a standalone branded website. Based on the page title, Japanese-language interface text, and the screenshot content, the page presents itself as a Windows security or help-desk themed screen and prompts the visitor to call a support number.
The visible content does not appear to represent an official corporate support portal. Instead, it imitates operating-system security warnings and overlays multiple alert-style windows, which is a pattern commonly associated with browser-based tech-support lures. The domain naming format, lack of recognizable branding ownership for the subdomain itself, and phishing/fraud categorizations from multiple web-classification sources suggest it may be a disposable campaign page rather than a legitimate long-term service.
Safety Assessment for hammerhead-app-ub55h.ondigitalocean.app
Scan results indicate substantial risk signals at the time of this scan. The URL was flagged by 15 out of 91 security engines, and multiple web-classification providers categorized it as phishing or fraud-related. The screenshot also shows a fake-looking Windows Defender / Microsoft support warning flow with a phone number and urgent messaging, which is consistent with social-engineering tactics used to pressure visitors into calling fraudulent support lines.
The malware scan reported suspicious findings on the main page files, although those detections were generic rather than tied to a named malware family. Threat-database checks were otherwise mostly clean, but the domain's IP address was listed on one mail-reputation blocklist, which is a weaker secondary signal and not, by itself, proof of malicious web content. In this case, the stronger indicators are the multi-engine phishing consensus and the deceptive page content shown in the screenshot.
Based on these findings, this website may pose potential risks to visitors.
Technical Description
The site uses a valid SSL certificate issued by a mainstream certificate authority and is served through Cloudflare infrastructure, with the resolved IP located in Canada. Nameservers are on Cloudflare, DNSSEC appears to be unsigned, and the domain is several years old, although age alone does not offset the content-based phishing indicators seen here.
The page appears to be hosted on a cloud app subdomain and references a Cloudflare challenge script as well as an outdated jQuery library URL. No iframe activity was reported in the scan data. The main technical concern is not the TLS setup but the apparent use of a hosted web app to deliver deceptive security-alert content that imitates Microsoft/Windows system messaging.
Share your experience with this website. Was it safe? Did you encounter any issues?