xindonesiacstmerns.fredped.biz.id
Category: Suspicious
To use full-featured product, you have to purchase a license for Combo Cleaner. Limited seven days free trial available. Combo Cleaner is owned and operated by RCS LT, the parent company of PCRisk.com.
Description of xindonesiacstmerns.fredped.biz.id
This website appears to present itself as a customer-care or account-service page for DANA, an Indonesian digital wallet and payments platform. The page title, branding, Indonesian-language text, and referenced assets suggest it is designed to resemble an official support or promotional page related to DANA services such as PayLater activation, installment activation, or balance refunds.
However, the domain name itself does not appear to match the official branding of the service it references. Instead, it uses a newly registered subdomain under an unrelated parent domain, while displaying DANA logos and links associated with the legitimate brand. Based on the page content and metadata, the site appears intended to collect user interaction under the appearance of financial-service support.
Safety Assessment for xindonesiacstmerns.fredped.biz.id
Multiple security signals indicate elevated risk at the time of this scan. The domain was flagged by 18 out of 91 security engines, and several web-classification sources categorized it as phishing or fraud-related. The page also appears to imitate a known financial brand while operating from an unrelated, very recently registered domain, which is a common pattern in credential-harvesting and payment-account scams.
Although the malware scan did not detect malicious files in the sampled page resources, that does not materially reduce the concern here because phishing pages often rely on simple HTML, images, and forms rather than malware payloads. The domain age of only 5 days, lack of ranking, and branding mismatch further increase suspicion. Based on these findings, this website may pose potential risks to visitors.
Technical Description
The site was reachable over HTTPS with a valid TLS certificate issued by a mainstream certificate authority, and it appears to be served through Cloudflare infrastructure on IP address 188.114.96.2. The nameservers also point to Cloudflare, suggesting use of a CDN or reverse-proxy layer. DNSSEC appears to be unsigned at the time of this scan.
From a technical standpoint, the presence of HTTPS alone should not be treated as a trust signal, since phishing pages commonly use valid certificates as well. No malicious files, flagged external links, or iframes were identified in the provided scan data, but the combination of a newly created domain, unrelated hostname structure, and brand-themed login/support content remains a notable concern.
Share your experience with this website. Was it safe? Did you encounter any issues?