meher-fund.org
Category: Phishing
To use full-featured product, you have to purchase a license for Combo Cleaner. Limited seven days free trial available. Combo Cleaner is owned and operated by RCS LT, the parent company of PCRisk.com.
Quttera Web Malware Removal is a paid subscription service. Pricing, plans, and trial availability are set by Quttera. Quttera is operated by Quttera Ltd, an independent third-party company unrelated to RCS LT. PCrisk.com may earn a referral commission when users sign up through this link.
Description of meher-fund.org
The domain meher-fund.org appears to present a login page styled as an Xfinity sign-in portal rather than content related to a fund, nonprofit, or organization suggested by the domain name. The page title shown is "Sign in to Xfinity," and the screenshot displays Xfinity branding, account sign-in fields, and promotional text associated with Xfinity mobile services.
Based on the visible content and linked resources, the site appears to imitate a telecommunications account-login experience and references assets from Xfinity-owned web properties. There is no clear indication in the provided scan data that meher-fund.org is operated by Xfinity or by an organization publicly associated with that brand, which raises concerns about the site's stated identity and purpose.
Safety Assessment for meher-fund.org
Multiple independent security signals indicate elevated risk at the time of this scan. The domain was flagged by 19 out of 91 security engines, with many of those detections classifying it as phishing or otherwise malicious. In addition, a major threat database listed the site for social-engineering activity, and the malware scan flagged suspicious use of Xfinity-related resources. The page content also appears to mimic an Xfinity login screen while being hosted on an unrelated domain, which may indicate an attempt to collect credentials by impersonating a known service.
There is also a secondary reputation concern: the domain's IP address was listed on one mail-reputation blocklist at the time of the scan. On its own, that type of listing is weaker than phishing detections, but in this case it adds to an already concerning picture rather than standing alone. The domain is also very new, not ranked for notable traffic, and uses branding that does not match the domain name.
Based on these findings, this website may pose potential risks to visitors.
Technical Description
The site was served through Cloudflare infrastructure from IP address 188.114.97.0, with hosting attributed to CloudFlare, Inc. and geolocation data pointing to Toronto, Canada. It presented a valid SSL certificate at the time of the scan, expiring on 2026-11-13, which means the connection may be encrypted in transit; however, valid HTTPS alone does not verify that the operator or page purpose is legitimate.
The domain is very recent, created on 2026-04-27, and its DNSSEC status is unsigned. Nameservers are betty.ns.cloudflare.com and odin.ns.cloudflare.com. A notable technical concern is the apparent use of external Xfinity-linked assets on a non-Xfinity domain while presenting a branded login interface, which is consistent with credential-harvesting patterns sometimes seen in phishing campaigns.
Share your experience with this website. Was it safe? Did you encounter any issues?