microsoftword.programgridsoft.com
Category: Phishing
To use full-featured product, you have to purchase a license for Combo Cleaner. Limited seven days free trial available. Combo Cleaner is owned and operated by RCS LT, the parent company of PCRisk.com.
Description of microsoftword.programgridsoft.com
This domain appears to present itself as a download page for Microsoft Word, using Microsoft branding, a Word-themed interface, and Russian-language marketing text that promotes an offline installer for "Word 2026." The page layout imitates a software product landing page and includes a prominent download button, suggesting that its purpose is to persuade visitors to obtain software directly from this site rather than through an official vendor channel.
Based on the domain structure, however, the page is hosted on a subdomain of programgridsoft.com rather than on an official Microsoft-owned domain. That mismatch, combined with the use of well-known product branding in the subdomain name itself, suggests the site may be attempting to resemble an official Microsoft Word download page. No evidence in the provided scan data indicates that Microsoft operates this domain.
Safety Assessment for microsoftword.programgridsoft.com
Multiple security signals indicate elevated risk at the time of this scan. The domain was flagged by 19 out of 91 security engines, with many of those detections classifying it as phishing or malicious. In addition, the page closely resembles an official Microsoft Word download page while using a non-Microsoft domain, which may indicate a look-alike site intended to exploit user trust in the Microsoft brand. The domain is also very new, has no established traffic ranking, and the page encourages visitors to download software directly.
The malware scan summary was mixed: it reported no flagged files in the small file sample scanned, but it also associated the domain and certain local resources with a generic malicious-object label. Blacklist data was not fully clean either: the domain's IP address is listed on one mail-reputation blocklist, and one additional blacklist source also recorded a generic malicious-object listing. While a mail-reputation listing alone would be a weak signal, it adds to the broader pattern here rather than standing alone.
Taken together, the combination of multi-engine phishing detections, brand-like presentation on an unrelated domain, and a newly registered software-download page materially increases concern. Based on these findings, this website may pose potential risks to visitors.
Technical Description
The site uses a valid Let's Encrypt SSL certificate, which indicates that HTTPS was configured at the time of the scan, but certificate presence alone does not verify legitimacy. The server appears to run nginx and resolves to IP address 185.40.155.13, hosted by Docker LTD in St Petersburg, Russia. The domain uses Cloudflare nameservers and is relatively new, with a registration age of about 143 days.
DNSSEC appears to be unsigned, so DNS responses do not benefit from DNSSEC validation. The scan data also notes flagged internal resources, including a JavaScript file and favicon path, under generic malicious-object classifications. In context, the technical setup looks functional but does not offset the stronger reputation and impersonation-related concerns identified elsewhere in the scan.
Share your experience with this website. Was it safe? Did you encounter any issues?