login.sharefiles.email
Category: Phishing
To use full-featured product, you have to purchase a license for Combo Cleaner. Limited seven days free trial available. Combo Cleaner is owned and operated by RCS LT, the parent company of PCRisk.com.
Description of login.sharefiles.email
The subdomain login.sharefiles.email appears to be part of an email-focused web property used for login or campaign-related landing pages. Based on the screenshot, the page currently displays a notice stating that the visit was part of an authorized phishing simulation, followed by educational content about spear phishing and how to recognize suspicious messages.
This suggests the site may be operated as part of a corporate security-awareness or phishing-training program rather than as a conventional public-facing service. The domain has been registered for several years through an enterprise-oriented registrar, which is broadly consistent with organizational use, although the exact operator is not identified in the provided scan data.
Safety Assessment for login.sharefiles.email
Scan results show mixed signals at the time of this scan. The domain was flagged by 8 out of 91 security engines, with several classifying it as phishing or malicious. At the same time, blacklist checks provided here were clean, and the page content shown in the screenshot appears to describe an authorized phishing simulation rather than an active credential-harvesting page. That combination can occur when training or simulation infrastructure resembles real phishing closely enough to trigger automated detections.
The domain name includes a login-themed subdomain, which can naturally attract scrutiny, and the page content explicitly references phishing simulation and spear-phishing awareness. While this context may reduce the likelihood that the page is intended for indiscriminate abuse, the multi-engine detection count is still a meaningful caution signal. Based on these findings, this website may pose potential risks in some contexts, or it may be part of a legitimate internal security training workflow. Visitors should rely on organizational context and avoid entering credentials unless they are certain the page is expected. Based on available scan data, caution is warranted at the time of this scan.
Technical Description
The site presented a valid Let's Encrypt TLS certificate expiring in August 2026, which indicates encrypted HTTPS connectivity was available at the time of testing. It resolves to an AWS EC2 address in the ap-southeast-2 region (Sydney, Australia), using AWS nameservers. The domain itself is relatively mature at about 9 years old and is registered through MarkMonitor, a registrar commonly used for managed corporate portfolios.
DNSSEC appears to be unsigned, so DNS responses may not benefit from that additional integrity layer. No malicious files, external links, or iframe references were identified in the supplied malware-scan details, and only one file was scanned. However, the lack of broader page artifacts in the scan output means the technical picture is limited to the observed landing page and infrastructure metadata.
Share your experience with this website. Was it safe? Did you encounter any issues?