roshade.co
Category: Malware Distribution
- Don't sign in or pay here. Close it. If you typed a password, change it where you normally use it.
- Already visited? Check your device. A free scan shows whether anything was installed.
- Stop the next one. Combo Cleaner's web protection blocks phishing and scam sites before they load.
Combo Cleaner is PCrisk's own anti-malware tool, owned by RCS LT. Free to scan; removing what it finds needs a licence (7-day free trial).
Description of roshade.co
roshade.co appears to present itself as a download and promotional website for "RoShade," a graphics enhancement tool aimed at Roblox players. Based on the page title, metadata, and screenshot, the site advertises visual effects such as ray tracing, ambient occlusion, reflections, and shader presets, with a prominent download button and feature-focused landing page design.
The site appears to target gaming users, particularly Roblox players looking to modify or enhance in-game visuals. No clear company identity, publisher details, or established operator information are visible in the provided scan data, and the domain itself is very new. The page also references an additional download-related domain, which may indicate that software delivery or redirection occurs outside the main site.
Safety Assessment for roshade.co
Multiple security signals raise concern at the time of this scan. The domain was flagged by 11 out of 91 security engines, with several classifying it as malware-related or otherwise malicious. In addition, the site is only 31 days old, has no established traffic ranking, and its linked assets and primary domain were marked by a malware scan with generic malicious-object detections. The page promotes a downloadable gaming-related tool, which is a common delivery pattern for unwanted or harmful software.
Blacklist and threat-database results were mixed rather than uniformly negative. Major content-malice databases in the provided scan data did not report active listings at the time of this scan, and DNS-based blocklists checked clean, but one additional blacklist source did list the domain with a generic suspicious classification. The page also links to a separate download domain, which may add uncertainty because software distribution is not confined to the main hostname.
Based on these findings, this website may pose potential risks to visitors.
Technical Description
The site uses a valid Let's Encrypt SSL certificate expiring on 2026-12-07 and is served over HTTPS, which helps encrypt traffic in transit but does not by itself indicate trustworthiness. The server appears to run nginx/1.28.3 on Ubuntu and is hosted by Dedik Services Limited on IP address 91.92.33.161 in Frankfurt am Main, Germany. Nameservers are provided through Cloudflare, while DNSSEC appears to be unsigned.
From a technical-risk perspective, the most notable concerns are the domain's very recent registration, the absence of DNSSEC, and the presence of downloadable assets that were generically flagged during scanning. The site also references an external download-related domain, which may complicate verification of the actual software delivery path.
Share your experience with this website. Was it safe? Did you encounter any issues?