wponedrivedocdownloaderqpegoamakadownloadpreviewbrassindexc.com
Category: Phishing
To use full-featured product, you have to purchase a license for Combo Cleaner. Limited seven days free trial available. Combo Cleaner is owned and operated by RCS LT, the parent company of PCRisk.com.
Description of wponedrivedocdownloaderqpegoamakadownloadpreviewbrassindexc.com
This domain appears to be a newly registered website with an unusually long, machine-generated-looking name that references terms such as "OneDrive," "doc," "download," and "preview." Based on the domain string alone, it may be intended to mimic a document-sharing or file-download workflow, potentially resembling cloud storage or document preview pages commonly used in business communications.
No clear brand, organization, or legitimate business identity is evident from the available scan data, and no category metadata was provided by classification sources. The infrastructure points to hosting in Russia with a standard web server and a valid TLS certificate, but the available evidence does not indicate an established operator, public-facing company profile, or recognizable service behind the domain.
Safety Assessment for wponedrivedocdownloaderqpegoamakadownloadpreviewbrassindexc.com
This domain was flagged by 3 out of 91 security engines at the time of this scan, including phishing-related detections from multiple sources. In addition, it was listed by a major threat database for social-engineering activity, which is a stronger warning sign than a generic heuristic alert. The domain is also extremely new at just 8 days old and has no visible traffic ranking, both of which can increase uncertainty when assessing legitimacy.
The domain name closely resembles a document-download or cloud-file preview workflow and may be designed to appear familiar to users expecting a shared file or online document. That pattern, combined with the phishing-related detections and threat-database listing, suggests elevated risk. Although the malware scan did not identify malicious files in the limited content checked, phishing pages often rely on deceptive page design rather than downloadable malware.
Based on these findings, this website may pose potential risks to visitors.
Technical Description
The site was using a valid Let's Encrypt SSL certificate at the time of this scan, expiring on 2026-11-07. A valid certificate helps encrypt traffic in transit, but it does not by itself indicate legitimacy. The server appeared to run LiteSpeed and resolved to IP address 176.32.38.50, hosted by BX Network in Moscow, Russia.
WHOIS data indicates the domain was registered very recently and is set to expire after one year, which is common for short-lived campaigns but not conclusive on its own. DNSSEC was not enabled, leaving the domain unsigned. No DNS-based mail-reputation blocklist hits were reported in the provided checks.
Share your experience with this website. Was it safe? Did you encounter any issues?