paypal.authia-rule.xyz
Category: Phishing, Spam
To use full-featured product, you have to purchase a license for Combo Cleaner. Limited seven days free trial available. Combo Cleaner is owned and operated by RCS LT, the parent company of PCRisk.com.
Description of paypal.authia-rule.xyz
This domain appears to present itself as a PayPal login page, with page metadata reading "Log in to your PayPal account" and a screenshot showing a payment-account sign-in form styled to resemble PayPal. Based on the domain structure, the site is not hosted on PayPal's official domain and instead uses the separate domain authia-rule.xyz with "paypal" placed as a subdomain label.
Available classification data associates the site with phishing and fraud-related categories rather than a legitimate financial service. The domain is very newly registered and does not appear to have an established traffic presence, which may be consistent with short-lived credential-harvesting pages rather than a long-standing consumer website.
Based on the visible content and naming pattern, the operator does not appear to be the official PayPal service. Instead, the page may be attempting to imitate a well-known payment platform's login experience in order to collect account credentials.
Safety Assessment for paypal.authia-rule.xyz
Multiple independent security signals indicate elevated risk at the time of this scan. The domain was flagged by 24 out of 91 security engines, and several web-classification sources categorized it as phishing or fraud-related. In addition, a major threat database listed the URL for social-engineering activity, which is a strong content-based warning signal.
The domain also closely resembles paypal.com and may be a look-alike intended to imitate that brand. This concern is reinforced by the screenshot, which shows a PayPal-branded login form on a non-official domain, as well as by the domain's very recent registration age of 6 days and lack of established ranking data. Although one malware scan reported no malicious files at the time of inspection, that result does not outweigh the broader phishing indicators.
The domain's IP address is also listed on one mail-reputation blocklist, which is a secondary cautionary signal. Based on these findings, this website may pose potential risks to visitors.
Technical Description
The site was reachable over HTTPS with a valid Let's Encrypt certificate expiring on 2026-09-25. It appears to be served by nginx from IP address 31.76.59.129, hosted by Ace Data Centers II, LLC in Orem, United States. The domain uses Cloudflare nameservers, while DNSSEC appears to be unsigned.
From a technical-risk perspective, the presence of TLS only indicates encrypted transport and should not be taken as proof of legitimacy. The combination of a newly created domain, unsigned DNSSEC status, non-ranked traffic profile, and a login page imitating a major financial brand may be consistent with a short-lived phishing setup.
Share your experience with this website. Was it safe? Did you encounter any issues?