rallack.spahotel.guru
Category: Phishing And Fraud
To use full-featured product, you have to purchase a license for Combo Cleaner. Limited seven days free trial available. Combo Cleaner is owned and operated by RCS LT, the parent company of PCRisk.com.
Description of rallack.spahotel.guru
This domain appears to present itself as a hospitality or hotel-booking website, and the page screenshot closely imitates the look and layout of a major travel reservation platform. The visible content shows accommodation search results, pricing, filters, and sign-in prompts consistent with an online travel booking service rather than an independent spa hotel website.
Based on the domain structure, rallack.spahotel.guru does not appear to be an official primary domain for a well-known booking brand. The hostname uses a subdomain format under spahotel.guru, while the page design appears intended to resemble a mainstream travel-booking interface. That combination may indicate a look-alike page designed to attract users seeking hotel reservations or account access.
Safety Assessment for rallack.spahotel.guru
Multiple security signals indicate elevated risk at the time of this scan. The domain was flagged by 18 out of 91 security engines, with many of those detections classifying it as phishing or fraud-related. In addition, several web-classification providers categorized the site as phishing and fraud, even though one provider labeled it under hospitality. The screenshot also shows a page that closely resembles a well-known hotel-booking brand, which may indicate an attempt to imitate that service and collect user credentials or other sensitive information.
Blacklist and threat-database results were mixed rather than fully clean. Major content-malice databases in the provided data did not report a listing at the time of this scan, but one blacklist provider did list the domain with a generic malicious designation. The malware crawl itself did not identify flagged files, links, or iframes, which can happen when phishing pages are visually deceptive rather than overtly malware-laden.
The domain has a valid certificate and is more than a year old, but those factors do not outweigh the stronger phishing indicators in the scan results and the apparent brand imitation visible in the screenshot. Based on these findings, this website may pose potential risks to visitors.
Technical Description
The site was served over HTTPS with a valid Let's Encrypt certificate expiring on 2026-08-30. It appears to be hosted on an nginx web server at IP address 52.29.26.157 in AWS EC2 infrastructure located in Frankfurt am Main, Germany. DNSSEC is signed, which may help protect DNS integrity, and the domain uses Spaceship nameservers.
From a technical standpoint, the basic web configuration appears functional, but the presence of valid TLS, cloud hosting, and DNSSEC should not be treated as proof of legitimacy. No malicious files, external links, or iframes were identified in the supplied crawl, suggesting the primary concern may be deceptive page content rather than exploit delivery.
Share your experience with this website. Was it safe? Did you encounter any issues?