php-web-server--activo2888.replit.app
Category: Phishing
To use full-featured product, you have to purchase a license for Combo Cleaner. Limited seven days free trial available. Combo Cleaner is owned and operated by RCS LT, the parent company of PCRisk.com.
Description of php-web-server--activo2888.replit.app
This domain appears to be a page hosted on Replit, a cloud development and app-hosting platform, rather than an official standalone business website. The page title and screenshot indicate that it presents a Spanish-language Microsoft sign-in interface (“Iniciar sesión en tu cuenta Microsoft”), suggesting that it is attempting to collect Microsoft account credentials or imitate a Microsoft login workflow.
Based on the visible content, the site does not appear to represent an independent service with its own branding, company identity, or published organizational information. Instead, it appears to reuse Microsoft branding, imagery, and login-page styling while operating from a third-party subdomain that is not associated with Microsoft's official web properties.
Safety Assessment for php-web-server--activo2888.replit.app
Multiple security signals indicate elevated risk at the time of this scan. The domain was flagged by 9 out of 91 security engines, with several classifying it as phishing, and it was also listed by a major threat database for social-engineering activity. In addition, the screenshot shows a Microsoft-branded login page hosted on a Replit subdomain rather than an official Microsoft domain, which may indicate an attempt to imitate a legitimate sign-in page and capture user credentials.
Although the malware scan did not identify malicious files and several blacklist databases were clean, those findings do not outweigh the stronger phishing-related indicators in this case. The absence of DNSBL listings is neutral, but the combination of multi-engine phishing detections, a social-engineering listing, and visible brand imitation materially increases concern. Based on these findings, this website may pose potential risks to visitors.
Technical Description
The site was reachable over HTTPS with a valid TLS certificate issued by Google Trust Services, and it appears to be served through Google Frontend infrastructure on Google Cloud. The server IP was 34.117.33.233, geolocated to Kansas City, United States. The domain uses Google-hosted nameservers and the parent domain has been registered for several years, though this does not by itself validate the legitimacy of the specific hosted subpage.
DNSSEC appears to be unsigned. No malicious files were flagged in the limited file scan, but the page includes externally loaded scripts and assets and is hosted on a shared app platform, which can make abuse easier to deploy quickly. The main technical concern here is not TLS failure, but the apparent mismatch between the Microsoft-themed login content and the non-Microsoft hosting domain.
Share your experience with this website. Was it safe? Did you encounter any issues?