to.lk
Category: Phishing
To use full-featured product, you have to purchase a license for Combo Cleaner. Limited seven days free trial available. Combo Cleaner is owned and operated by RCS LT, the parent company of PCRisk.com.
Quttera Web Malware Removal is a paid subscription service. Pricing, plans, and trial availability are set by Quttera. Quttera is operated by Quttera Ltd, an independent third-party company unrelated to RCS LT. PCrisk.com may earn a referral commission when users sign up through this link.
Description of to.lk
The domain to.lk appears to host a URL-shortening service branded as "ShortURL" and linked closely with shorturl.lk. Based on the page title, metadata, and screenshot, the site offers users a way to create shortened links, manage accounts, and track link activity for branding or analytics purposes. The homepage includes standard navigation items such as features, support, pricing, login, and sign-up, which suggests a web application rather than a simple landing page.
The domain itself is very old and uses Sri Lanka's .lk namespace, but the visible service appears to be a modern link-shortening platform rather than a government or institutional site. The operator is not clearly identified in the provided scan data, so ownership cannot be confirmed from this snapshot alone. Functionally, the site appears intended for link redirection, sharing, and campaign tracking, which are common uses for short-link services.
Safety Assessment for to.lk
This website raises significant concerns based on the available scan results. At the time of this scan, it was flagged by 12 out of 91 security engines, with multiple detections describing the site as phishing or malicious. In addition, the malware scan marked numerous pages and assets as suspicious or malicious, including login, sign-up, pricing, privacy, and contact-related paths. A URL-shortening service can also introduce additional risk because shortened links may obscure the final destination from visitors.
Blacklist and reputation data also show adverse signals. While some major content-malice databases were clean at the time of this scan, the domain was listed by at least one phishing-focused threat database and another malware-oriented provider. The domain's IP address is also listed on one mail-reputation blocklist, which is a weaker signal than direct website-malice detections but still worth noting as a caution.
The site does present as a functioning service rather than a parked page, and the domain age is unusually long, which can sometimes indicate an established asset. However, the multi-engine phishing consensus is a much stronger signal than age alone. Based on these findings, this website may pose potential risks to visitors.
Technical Description
The site uses a valid Let's Encrypt SSL certificate that, at the time of this scan, was set to expire on 2026-10-10. DNSSEC appears to be enabled and signed, which is a positive integrity signal for DNS responses. The web server is reported as LiteSpeed, hosted on infrastructure associated with PrivateSystems Networks EU Ltd in Amsterdam, Netherlands.
From a security perspective, the main concerns are not the TLS setup itself but the reputation findings around the hosted content and linked resources. The scan also shows extensive internal references between to.lk and shorturl.lk, suggesting the service may operate across both domains. No protocol-level weakness was provided in the scan data, but the content-level detections are substantial enough to outweigh otherwise routine infrastructure signals.
Share your experience with this website. Was it safe? Did you encounter any issues?