handsome-blue-j4s00ofr.edgeone.dev
Category: Phishing And Other Frauds
To use full-featured product, you have to purchase a license for Combo Cleaner. Limited seven days free trial available. Combo Cleaner is owned and operated by RCS LT, the parent company of PCRisk.com.
Description of handsome-blue-j4s00ofr.edgeone.dev
The domain handsome-blue-j4s00ofr.edgeone.dev appears to be hosted on a developer-oriented subdomain under edgeone.dev rather than on a standalone branded website. Based on the screenshot, the page presents what looks like a document-viewing interface styled to resemble a cloud PDF or file-sharing portal, with a prompt asking the visitor to confirm an email address and password in order to view a protected PDF document.
The visible content suggests the page may be attempting to imitate a familiar document-access workflow commonly associated with online PDF storage or e-signature platforms. There is no clear evidence of an independent business identity, publisher information, or normal corporate website content on the page. The combination of a generic subdomain, minimal metadata, and a credential-entry form centered on document access may indicate that the site is being used for a narrow campaign-focused purpose rather than as a conventional public website.
Safety Assessment for handsome-blue-j4s00ofr.edgeone.dev
Scan results indicate elevated risk signals for this domain at the time of this scan. It was flagged by 7 out of 91 security engines, with multiple detections describing the page as phishing or malicious, and one threat database also listed it for phishing. In addition, a web-classification provider categorized the domain under phishing and fraud-related activity. Although the malware scan did not identify malicious files in the limited content it checked, that does not offset the stronger reputation-based phishing indicators.
The screenshot adds further concern because the page appears to mimic a document portal and asks visitors to enter both email credentials and a password to access a PDF. That pattern is commonly associated with credential-harvesting pages, especially when presented on a generic developer-hosted subdomain rather than an official branded domain. The domain also lacks meaningful site identity signals and does not appear to have established web presence indicators such as a traffic ranking.
Based on these findings, this website may pose potential risks to visitors.
Technical Description
The site uses a valid SSL certificate issued by a mainstream certificate authority, which means the connection appears to be encrypted in transit; however, HTTPS alone does not indicate legitimacy. The server appears to be hosted on edgeone-pages infrastructure at IP address 43.174.246.29 in Singapore, with hosting attributed to ACE. The domain is about 1 year old, uses MarkMonitor as registrar, and its DNSSEC status is unsigned.
No malicious files, external links, or iframes were identified in the limited scan data provided, but the page title is generic ("continue") and the overall setup appears lightweight and campaign-like. The main technical concern is not the TLS setup but the apparent use of a disposable-looking subdomain and a login-style form that may be intended to collect credentials.
Share your experience with this website. Was it safe? Did you encounter any issues?