ray-diun.cfd
Category: Phishing And Other Frauds
To use full-featured product, you have to purchase a license for Combo Cleaner. Limited seven days free trial available. Combo Cleaner is owned and operated by RCS LT, the parent company of PCRisk.com.
Description of ray-diun.cfd
The domain ray-diun.cfd appears to present itself as a cryptocurrency staking platform branded as "Raydium Staking." Based on the page title, screenshot, and on-page labels such as Swap, Liquidity, Portfolio, Perpetuals, LaunchLab, and Connect Wallet, the site appears to target users interested in decentralized finance on the Solana ecosystem. The interface lists staking options for tokens such as RAY, SOL, USDC, USDT, JUP, and related assets, suggesting a wallet-connected crypto service rather than a general informational website.
The domain name does not appear to match the well-known Raydium brand's primary naming pattern and instead uses a newly registered .cfd domain. That combination may indicate an unofficial third-party project, a promotional clone, or a site attempting to resemble an established crypto platform. Based on available data, the operator is not clearly identified in the scan details provided, and the site is fronted by a content delivery and protection layer rather than exposing a distinct origin host.
Safety Assessment for ray-diun.cfd
This domain shows mixed signals at the time of this scan. One out of 91 security engines flagged it as phishing, while other malware scanning results did not detect malicious files and major threat databases listed in the scan were clean. However, the site is very new at 65 days old, has no established traffic ranking, and presents a financial or wallet-connected cryptocurrency interface, which is a higher-risk category for impersonation and credential or wallet-drain attempts.
The page branding closely resembles Raydium, but the domain itself is ray-diun.cfd rather than a more expected official brand domain. That resemblance may indicate a look-alike website designed to appear associated with a known crypto service. The screenshot also shows a wallet connection prompt and unusually high staking APR figures, which can be used on deceptive crypto pages to encourage quick interaction.
Based on available scan data, no broad malware distribution was detected at the time of this scan, but the combination of a phishing-related classification, a very recent registration, and branding that may resemble an established crypto platform suggests elevated caution. Based on these findings, this website may pose potential risks to visitors.
Technical Description
The site uses a valid Let's Encrypt SSL certificate expiring on 2026-09-16 and is served through Cloudflare infrastructure on IP address 188.114.96.0, with hosting geolocated to Toronto, Canada based on available IP data. Nameservers are set to Cloudflare, and the observed link path includes a challenge-platform URL, which is consistent with bot-protection or access filtering. DNSSEC appears to be unsigned.
From the scan data provided, no malicious files, flagged external links, or iframe-based threats were detected at the time of analysis. Even so, the combination of Cloudflare fronting, limited exposed infrastructure details, and a newly registered domain means technical transparency is relatively low, which is common for both legitimate modern sites and short-lived deceptive campaigns.
Share your experience with this website. Was it safe? Did you encounter any issues?