security.live.com.office.u24o365.mcafee.devshn.net
Category: Phishing
To use full-featured product, you have to purchase a license for Combo Cleaner. Limited seven days free trial available. Combo Cleaner is owned and operated by RCS LT, the parent company of PCRisk.com.
Description of security.live.com.office.u24o365.mcafee.devshn.net
This domain is a deeply nested subdomain under devshn.net and uses multiple well-known security and productivity brand terms in its hostname, including references to Microsoft 365, Live, Office, and McAfee. Based on the naming pattern alone, it appears designed to resemble a security or account-related service page rather than a straightforward standalone business website.
There is no clear evidence in the provided scan data of a normal public-facing service, publisher identity, or legitimate site content associated with this exact hostname. The combination of brand-like labels in the subdomain and the absence of ordinary website context may indicate that the page is intended to attract users who believe they are interacting with a trusted login, security alert, or account verification portal.
Safety Assessment for security.live.com.office.u24o365.mcafee.devshn.net
Multiple security engines flagged this URL at the time of the scan, with 12 out of 91 detections and several classifying it as phishing or malicious. That level of multi-engine agreement is a meaningful risk signal, especially for a hostname that closely resembles trusted brand and account-security terminology. Although some blacklist sources were clean and one malware scan did not identify malicious page files, those signals do not outweigh the phishing-oriented detections for this specific URL.
The domain itself appears crafted to look like it belongs to familiar online services, which may increase the chance of user confusion. Even though the parent domain is relatively old, age alone does not reduce concern when a specific subdomain shows strong phishing-related indicators. Based on these findings, this website may pose potential risks to visitors.
Technical Description
The site presented a valid SSL/TLS certificate at the time of the scan, issued for infrastructure associated with a network security provider, and it was hosted on AWS EC2 in the ap-southeast-2 region with an IP address located in Sydney, Australia. A valid certificate helps encrypt traffic in transit, but it does not by itself confirm legitimacy or trustworthiness.
DNSSEC appears to be unsigned, which means DNS responses may not benefit from that additional integrity layer. The hostname uses a long, brand-heavy subdomain structure and is backed by cloud hosting rather than clearly identifiable first-party infrastructure, which can be consistent with disposable or campaign-style phishing deployments.
Share your experience with this website. Was it safe? Did you encounter any issues?