owa.donationsnonprofit.com
Category: Security Awareness Training
To use full-featured product, you have to purchase a license for Combo Cleaner. Limited seven days free trial available. Combo Cleaner is owned and operated by RCS LT, the parent company of PCRisk.com.
Description of owa.donationsnonprofit.com
The subdomain owa.donationsnonprofit.com appears to be an Outlook Web Access-style endpoint or campaign landing page associated with an organization’s email security awareness program. The screenshot does not show a credential form or a normal business homepage; instead, it displays a notice stating that the visitor reached an authorized phishing simulation, followed by educational content about spear phishing and how to recognize suspicious emails.
Based on the visible page content, this site appears to be used for internal security training rather than public-facing commerce or general content publishing. The parent domain name suggests a nonprofit-related context, while the “owa” subdomain naming convention may have been chosen to resemble a common enterprise mail access URL as part of a phishing-awareness exercise.
The domain has been registered for several years and uses enterprise-oriented infrastructure choices, including a corporate registrar and cloud hosting. That combination may be consistent with an organization-operated training or awareness asset, although the exact operator is not identified in the provided scan data.
Safety Assessment for owa.donationsnonprofit.com
Scan results show a mixed picture at the time of this scan. On one hand, 17 out of 91 security engines flagged the URL, largely with phishing-related verdicts, and one threat database listing was also present. On the other hand, major content-malware and phishing blocklists included in the scan were otherwise clean, the malware scan did not identify malicious files, and the screenshot itself presents the page as an authorized phishing simulation rather than an active credential-harvesting page.
This pattern can occur when a phishing-simulation or security-training page intentionally imitates phishing themes closely enough to trigger automated detections. The visible content explicitly says the page was part of an authorized phishing simulation and provides anti-phishing guidance, which materially reduces the likelihood that this specific page is attempting to steal credentials from ordinary visitors. Even so, the relatively high number of phishing-related engine detections means the URL may still be treated cautiously by browsers, filters, or endpoint tools.
Based on the available data, this appears more likely to be a security-awareness training page than a live phishing operation, but automated scanners have nevertheless identified notable phishing-like characteristics at the time of this scan. Based on these findings, the website may present limited practical risk to general visitors, while still carrying reputational or filtering risk due to its phishing-simulation behavior.
Technical Description
The domain is approximately 9 years old, registered through MarkMonitor, and resolves to an AWS EC2 IP in Sydney, Australia. It uses a valid Let's Encrypt SSL certificate with expiry in August 2026. DNSSEC appears to be unsigned, which is common but means DNS responses do not benefit from DNSSEC validation.
No malicious files, external links, or iframes were identified in the provided malware scan, and blacklist checks were mostly clean aside from one generic threat-database listing. The web server software and negotiated TLS protocol were not identified in the scan output, so the server stack cannot be fully assessed from the available data.
Share your experience with this website. Was it safe? Did you encounter any issues?