p2j3l2g67po7.shares.zrok.io
Category: Information Technology, Suspicious
To use full-featured product, you have to purchase a license for Combo Cleaner. Limited seven days free trial available. Combo Cleaner is owned and operated by RCS LT, the parent company of PCRisk.com.
Description of p2j3l2g67po7.shares.zrok.io
This domain appears to host a web-based tool branded as "@java980 - Matrix Leads Tool". Based on the page title, screenshot, and on-page labels such as "Matrix Elite Spain Mobile Leads System," the site appears to offer lead-generation or phone-number validation functionality, allowing users to paste lists of mobile numbers and generate or check leads. The design is minimal and utility-focused rather than informational, with a contact reference to a Telegram handle.
The domain itself is a subdomain under zrok.io rather than a standalone branded business domain, which may indicate a temporary, tunneled, or externally exposed service rather than a conventional public-facing company website. No clear operator identity, company details, legal pages, or organizational attribution are visible from the provided scan data, so the actual entity behind the tool is not readily verifiable based on available information.
Safety Assessment for p2j3l2g67po7.shares.zrok.io
Several scan signals suggest elevated risk at the time of this scan. The domain was flagged by 6 out of 91 security engines, with multiple detections describing it as phishing, malicious, suspicious, or fraud-related. In addition, multiple web-classification providers categorized the site as phishing, fraud-related, or suspicious. While one malware scan did not identify malicious files in the limited set it checked, that result does not outweigh the broader reputation signals and the nature of the page content.
The page itself appears to present a lead-generation or phone-number processing tool with limited transparency about who operates it, and it uses a random-looking subdomain rather than a clearly branded primary domain. That combination may increase uncertainty for visitors, especially when paired with phishing-related classifications from several independent sources. Blacklist and threat-database checks for major content-malice feeds were clean at the time of this scan, which is a mitigating factor, but the multi-engine detections remain a meaningful concern.
Based on these findings, this website may pose potential risks to visitors.
Technical Description
The site was reachable over HTTPS with a valid TLS certificate issued through Amazon infrastructure, expiring in February 2027. It resolves to an AWS Global Accelerator IP in Montreal, Canada, and the reported web stack includes Apache/2.4.58 on Win64 with OpenSSL 3.1.3 and PHP 8.2.12. The domain has been registered for about four years, which is older than many throwaway domains, but it is hosted as a subdomain under zrok.io rather than on a dedicated brand domain.
DNSSEC appears to be unsigned, which is common but means DNS responses do not benefit from that additional integrity layer. No DNS-based blocklist hits were reported at the time of this scan. The main technical concern is therefore not the certificate or hosting setup, but the reputation signals and the limited transparency of the service presented on the page.
Share your experience with this website. Was it safe? Did you encounter any issues?