xfvhg-pmsm-npe5.p-mv4ac1tf.workers.dev
Category: Hosting, Phishing
To use full-featured product, you have to purchase a license for Combo Cleaner. Limited seven days free trial available. Combo Cleaner is owned and operated by RCS LT, the parent company of PCRisk.com.
Description of xfvhg-pmsm-npe5.p-mv4ac1tf.workers.dev
This domain appears to be a Cloudflare Workers-hosted web endpoint rather than a conventional branded website. The hostname is a long, random-looking subdomain under workers.dev, which is commonly used for serverless applications, temporary web apps, redirects, and custom hosted pages. The visible page in the screenshot is minimal and shows only a loading-style message stating "Preparing your secure document...", without clear branding, company identification, or normal site navigation.
Based on the domain structure, page presentation, and classification data, this URL may be functioning as a transient delivery page or intermediary landing page rather than a full public-facing service. Multiple web-classification sources associate it with phishing or fraud-related activity at the time of this scan, while another category labels it as hosting, which is consistent with the underlying workers.dev platform being used to serve custom content.
Safety Assessment for xfvhg-pmsm-npe5.p-mv4ac1tf.workers.dev
This URL was flagged by 16 out of 91 security engines at the time of this scan, with many of those detections describing phishing-related behavior. In addition, multiple web-classification providers categorized the page as phishing, fraud, or hosting associated with suspicious activity. Although one malware scan reported no flagged files and several blacklist databases were clean, the multi-engine consensus is a stronger signal here than a single clean file scan, especially for a sparse page that may be intended to collect credentials or deliver deceptive content dynamically.
The screenshot also raises concern because it shows a vague "secure document" loading message with no visible organization name, document source, or user context. That kind of generic prompt may be used on credential-harvesting pages or staged access screens, particularly when paired with an unbranded, random-looking subdomain. The domain itself is older, which can sometimes reduce risk, but age alone does not offset the number of phishing-related detections seen here.
Based on these findings, this website may pose potential risks to visitors.
Technical Description
The site is served over HTTPS with a valid Let's Encrypt certificate and is hosted behind Cloudflare infrastructure on IP address 172.67.194.26. The hostname is a subdomain of workers.dev, indicating deployment through Cloudflare's serverless platform rather than a standalone domain with its own branded web presence. DNSSEC appears to be unsigned, and the nameservers are Cloudflare-operated.
From a security perspective, the main concern is not the TLS setup but the combination of hosting context, minimal page content, and the number of phishing-related detections from security engines. No malicious files, external links, or iframes were identified in the provided scan snapshot, which may simply reflect that the page is lightweight or dynamically generated.
Share your experience with this website. Was it safe? Did you encounter any issues?