wyvern.sh
Category: Malicious, Spam
To use full-featured product, you have to purchase a license for Combo Cleaner. Limited seven days free trial available. Combo Cleaner is owned and operated by RCS LT, the parent company of PCRisk.com.
Quttera Web Malware Removal is a paid subscription service. Pricing, plans, and trial availability are set by Quttera. Quttera is operated by Quttera Ltd, an independent third-party company unrelated to RCS LT. PCRisk.com may earn a referral commission when users sign up through this link.
Description of wyvern.sh
wyvern.sh appears to be a software-related website promoting a downloadable mod loader for mono/unity games. Based on the page title, meta description, and visible navigation, the site offers a loader download, feature pages, an "astra" mod menu section, Gorilla Tag-related mods, developer resources, and community links such as Discord and contact pages.
The site presents itself as a technology project rather than a general-content website or online store. Its branding is minimal and the homepage functions as a landing page for software distribution and related tools. Ownership details are not clearly presented on the homepage beyond the Wyvern name, so the operator appears to be an individual or small team associated with that project rather than a clearly identified company.
Safety Assessment for wyvern.sh
This domain shows a mixed but concerning risk profile at the time of this scan. It was flagged by 8 out of 92 security engines, and one blacklist-style source also listed it with a generic malicious-object label. In addition, the site is relatively new, not ranked by major popularity measurements, and it offers executable downloads such as loader and updater files, which can increase risk if the software is unverified or modified.
The page content indicates software distribution focused on game modding and mod-loader functionality. That type of content can sometimes attract detections because it may involve code injection, game modification, or tools that some security systems classify as unwanted or risky even when not overtly destructive. However, the combination of multiple engine detections, a suspicious file finding in the page scan, and downloadable executable components means caution would be warranted.
Based on these findings, this website may pose potential risks to visitors at the time of this scan.
Technical Description
The domain is using a valid TLS certificate issued by a mainstream certificate authority, with expiry shown in 2026. It is routed through Cloudflare infrastructure, while the observed web server layer reports ddos-guard, and the resolved IP is 104.21.81.38 with geolocation data pointing to Toronto, Canada. The domain uses Cloudflare nameservers and DNSSEC appears to be unsigned.
From a security posture perspective, the presence of HTTPS is positive, but it should not be treated as a trust signal by itself. The domain is young, DNSSEC is not enabled, and the site distributes Windows executable files, which raises the importance of independent file verification and reputation checks before download or execution.
Share your experience with this website. Was it safe? Did you encounter any issues?