lambent-snickerdoodle-40fd2d.netlify.app
Category: Phishing
To use full-featured product, you have to purchase a license for Combo Cleaner. Limited seven days free trial available. Combo Cleaner is owned and operated by RCS LT, the parent company of PCRisk.com.
Quttera Web Malware Removal is a paid subscription service. Pricing, plans, and trial availability are set by Quttera. Quttera is operated by Quttera Ltd, an independent third-party company unrelated to RCS LT. PCrisk.com may earn a referral commission when users sign up through this link.
Description of lambent-snickerdoodle-40fd2d.netlify.app
This domain is a Netlify-hosted subdomain presenting a page titled "Roblox" with a login form in Russian. Based on the screenshot and metadata, the page appears to imitate a Roblox account sign-in screen rather than functioning as a distinct branded service of its own. The content is minimal and centered on collecting a username and password.
The site appears to be operated through Netlify's hosting infrastructure rather than a dedicated standalone domain owned by a recognizable organization. Although one web-classification source labeled it as gaming, the page behavior and branding shown in the screenshot more closely resemble an account portal associated with a popular gaming platform.
Safety Assessment for lambent-snickerdoodle-40fd2d.netlify.app
Multiple scan signals indicate elevated risk at the time of this scan. The domain was flagged by 16 out of 91 security engines, and several web-classification providers categorized it as phishing or fraud-related. The page screenshot shows a Roblox-branded login prompt on an unrelated Netlify subdomain, which may indicate an attempt to capture account credentials by imitating a well-known gaming service.
The malware scan also flagged both scanned page entries and identified a Telegram API endpoint used to send submitted data, which is a pattern often associated with credential collection workflows. In addition, the domain's IP address is listed on one mail-reputation blocklist; this is a weaker signal than direct phishing detections, but it adds a small amount of caution rather than reassurance.
Based on these findings, this website may pose potential risks to visitors.
Technical Description
The site uses a valid SSL certificate issued by DigiCert and is hosted on Netlify infrastructure backed by AWS EC2 in Frankfurt, Germany. The domain itself is relatively old for a hosted subdomain context, with creation dating to 2018, and it resolves through NS1 nameservers.
DNSSEC appears to be unsigned. While the presence of HTTPS helps encrypt traffic in transit, it does not by itself validate the legitimacy of the page content. The main technical concern here is not TLS configuration but the apparent phishing-style login page and the flagged outbound Telegram API submission endpoint.
Share your experience with this website. Was it safe? Did you encounter any issues?