validaciionlive.fwh.is
Category: Phishing
To use full-featured product, you have to purchase a license for Combo Cleaner. Limited seven days free trial available. Combo Cleaner is owned and operated by RCS LT, the parent company of PCRisk.com.
Description of validaciionlive.fwh.is
This domain appears to host a login page presented in Spanish as a Microsoft account sign-in screen (“Iniciar sesión en tu cuenta Microsoft”). The page title, branding elements, and referenced image assets suggest it is attempting to resemble Microsoft's authentication interface rather than offering independent content or a distinct service of its own.
Based on the available page metadata and screenshot, the site does not appear to represent an official Microsoft-owned domain. Instead, it appears to be a standalone page hosted on infrastructure associated with a third-party hosting provider, using Microsoft-themed visual assets and a simple credential-entry form. That combination is commonly associated with credential-harvesting or brand-impersonation pages.
Safety Assessment for validaciionlive.fwh.is
Multiple security signals indicate elevated risk at the time of this scan. The domain was flagged by 10 out of 91 security engines, with several classifying it as phishing or malicious. In addition, one blacklist database listed the domain, and the page content appears to imitate a Microsoft login experience while being served from an unrelated domain. The screenshot, page title, and linked Microsoft-themed assets all reinforce the possibility that this page may be attempting to collect account credentials by resembling a trusted brand.
The malware scan summary was mixed: no files were formally flagged in the file count, but the scanner still associated the domain and one linked script path with a generic malicious-object label. While generic heuristic labels alone can be low-confidence, they are more concerning here because they appear alongside broad multi-engine phishing detections and visible brand imitation. The domain also has no meaningful traffic ranking in the provided data, which may be consistent with a low-visibility or short-lived campaign page.
Based on these findings, this website may pose potential risks to visitors.
Technical Description
The site was reachable over HTTPS with a valid TLS certificate issued by ZeroSSL, expiring on 2026-07-18. A valid certificate only indicates encrypted transport and does not by itself confirm legitimacy. The server appears to run openresty on IP address 185.27.134.34, hosted by I FastNet LTD in the United Kingdom. DNSSEC is not enabled, and the domain uses ns1.byet.org through ns4.byet.org nameservers.
From a technical-risk perspective, the most notable concerns are the phishing-related multi-engine detections, the use of a third-party hosted subdomain rather than an official brand domain, and a flagged script URL on the same host. Blacklist checks were otherwise largely clean apart from one listing, which suggests the strongest concerns come from content and reputation signals rather than mail-reputation data.
Share your experience with this website. Was it safe? Did you encounter any issues?