secure-bots[.]xyz
Category: Phishing
To use full-featured product, you have to purchase a license for Combo Cleaner. Limited seven days free trial available. Combo Cleaner is owned and operated by RCS LT, the parent company of PCRisk.com.
Description of secure-bots[.]xyz
The domain secure-bots[.]xyz appears to host a simple landing page styled to resemble a Telegram group or channel invitation page. Based on the screenshot and page title, its apparent purpose is to encourage visitors to click through to join a chat or channel, with branding and layout that imitate Telegram's familiar interface.
The site does not appear to present clear information about an operator, organization, or legitimate business behind it. Its content is minimal, and the domain name itself does not obviously correspond to Telegram or to a known publisher. The screenshot also suggests the page may be promoting adult-oriented community content rather than serving as an official messaging-platform property.
Safety Assessment for secure-bots[.]xyz
Several risk indicators are present at the time of this scan. The domain was flagged by 7 out of 91 security engines, with detections broadly associated with phishing, malware, or suspicious activity. In addition, the site is extremely new, with a registration age of only 4 days, and it has no established popularity ranking. Those factors can be consistent with short-lived campaign infrastructure.
The page also appears to imitate Telegram branding and presentation while operating from an unrelated third-party domain. That resemblance may indicate a look-alike page intended to redirect users, collect clicks, or funnel traffic to external content. Although the malware file scan did not identify malicious files and blacklist checks were clean at the time of this scan, those results do not outweigh the combination of multi-engine detections, very recent registration, and brand-like presentation on a non-official domain.
Based on these findings, this website may pose potential risks to visitors.
Technical Description
The site uses a valid Let's Encrypt TLS certificate and is fronted by Cloudflare infrastructure, with the server resolving to a Cloudflare IP in Toronto, Canada. Nameservers also point to Cloudflare, which may help obscure the origin server. DNSSEC appears to be unsigned, which is not uncommon but does mean DNS responses do not benefit from that additional integrity layer.
From a security-review perspective, the main concerns are not the basic TLS setup but the domain's very recent creation date, lack of reputation history, and the mismatch between the domain name and the branded content shown on the page. The scan found only two files and no flagged file artifacts, but the page's lightweight structure and external resource usage suggest it may function primarily as a redirect or lure page rather than a full standalone service.
Share your experience with this website. Was it safe? Did you encounter any issues?