submit-application.surge.sh
Category: Phishing
To use full-featured product, you have to purchase a license for Combo Cleaner. Limited seven days free trial available. Combo Cleaner is owned and operated by RCS LT, the parent company of PCRisk.com.
Description of submit-application.surge.sh
This URL appears to be a subdomain hosted on Surge, a static web publishing platform, rather than a standalone branded domain. The page title, "Meta - Account Review," and the screenshot suggest it is presenting itself as an account-related review or verification page associated with Meta's social platforms. The visible interface includes a language-selection dialog and branding elements that resemble a social media account support workflow.
Based on the domain structure and page presentation, this page may have been set up to imitate an account review or appeal process rather than serve as an official corporate property. The use of a free-hosting style subdomain instead of an official Meta-owned domain is notable, and the available categories from web-classification providers largely place it in phishing or fraud-related classifications.
Safety Assessment for submit-application.surge.sh
Multiple independent signals indicate elevated risk at the time of this scan. The URL was flagged by 19 out of 91 security engines, with many of those detections describing phishing or fraud-related behavior. In addition, multiple web-classification providers categorized the page as phishing or similar fraudulent activity. The screenshot and page title also suggest the site may be attempting to resemble a Meta account review page, which can be consistent with credential-harvesting or social engineering patterns.
Blacklist results were mixed rather than fully clean. While several major threat databases did not report the domain at the time of this scan, the URL was listed by one phishing-focused threat database, and the domain's IP address was also listed on one mail-reputation blocklist. That DNS-based listing is a weaker signal than direct phishing detections, but it still adds some caution and means the reputation picture was not entirely clean.
The malware scan did not detect malicious files in the limited content it checked, but that does not outweigh the broader phishing consensus from security engines and the deceptive-looking page presentation. Based on these findings, this website may pose potential risks to visitors.
Technical Description
The site was served over HTTPS with a valid TLS certificate issued by Sectigo and expiring in December 2026. It appears to be hosted on DigitalOcean infrastructure and delivered through the Surge platform, using Surge nameservers. DNSSEC was not enabled at the time of this scan, which is common but means DNS responses do not benefit from that additional authenticity control.
From a hosting perspective, this looks like a lightweight static deployment rather than a deeply provisioned enterprise environment. The page referenced a small number of external resources, including fonts, a media asset, and a Facebook help URL, and no iframes were observed. Although the certificate was valid and the page did not show file-based malware in the available scan, the stronger concern here appears to be potential phishing content rather than exploit delivery.
Share your experience with this website. Was it safe? Did you encounter any issues?