validaracceso-bhdactivarusuario.iceiy.com
Category: Phishing
To use full-featured product, you have to purchase a license for Combo Cleaner. Limited seven days free trial available. Combo Cleaner is owned and operated by RCS LT, the parent company of PCRisk.com.
Description of validaracceso-bhdactivarusuario.iceiy.com
The subdomain validaracceso-bhdactivarusuario.iceiy.com appears to have been used for a login- or account-activation themed page, likely targeting Spanish-speaking users. The wording in the hostname translates roughly to "validate access" and "activate user," which suggests an attempt to imitate an account verification or banking-related workflow rather than a standalone public website or business service.
Based on the available categorization data, multiple web-classification providers associate this address with phishing or fraud-related activity. At the time of this scan, the visible page no longer showed an active login form; instead, it displayed a hosting-provider suspension notice stating that the domain had been suspended for reaching server limits or a similar issue.
The domain itself is a subdomain under iceiy.com rather than a clearly branded standalone corporate domain, and no evidence in the scan data identifies a legitimate organization operating this specific subdomain. That combination of account-themed naming, phishing-related classifications, and the current suspension page may indicate that the address was previously used for deceptive credential collection or similar abuse.
Safety Assessment for validaracceso-bhdactivarusuario.iceiy.com
Scan results indicate elevated risk signals at the time of this scan. The URL was flagged by 15 out of 91 security engines, and multiple classification sources labeled it as phishing or fraud-related. In addition, it was listed by major threat databases for social-engineering activity, which is a stronger indicator than a generic heuristic alert and suggests prior reports or detections related to deceptive behavior.
The current screenshot shows a suspended hosting page rather than active phishing content, which may mean the original content has been removed or disabled. However, a suspended page does not negate earlier detections, and the domain's IP address is also listed on one mail-reputation blocklist, which adds a minor cautionary signal even though that type of listing is less conclusive for website content than phishing databases.
The malware scan summary did not detect malicious files in the limited files scanned, but that clean result is outweighed here by the broader multi-engine phishing consensus and blacklist listings. Based on these findings, this website may pose potential risks to visitors.
Technical Description
The site presented a valid SSL certificate issued by ZeroSSL, expiring in September 2026. It resolves to IP address 185.27.134.176 and appears to be served by openresty/1.31.1.1 on infrastructure associated with I FastNet LTD in the United Kingdom. DNSSEC is not enabled for the domain, so DNS responses do not appear to benefit from DNSSEC validation.
From an infrastructure perspective, the page currently serves a hosting-provider suspension notice rather than normal site content. The domain is about five years old, which by itself would usually be a stabilizing signal, but age alone does not offset the phishing-related detections seen in this scan. The use of a free-hosting style nameserver set and an unsigned DNS configuration may modestly increase uncertainty when combined with the reported abuse indicators.
Share your experience with this website. Was it safe? Did you encounter any issues?