xinewsdna-formindo.revolusioner.web.id
Category: Phishing
To use full-featured product, you have to purchase a license for Combo Cleaner. Limited seven days free trial available. Combo Cleaner is owned and operated by RCS LT, the parent company of PCRisk.com.
Description of xinewsdna-formindo.revolusioner.web.id
This domain appears to host a page themed around DANA, an Indonesian digital wallet and payments platform. The page title, branding, and on-page text suggest it is presenting itself as a customer-care or account-service portal, with options related to account recovery and payment features. The screenshot shows DANA logos and references to Indonesian financial and e-commerce entities, indicating that the page is likely targeting Indonesian users.
However, the domain itself does not appear to be an official DANA domain. Instead, it is hosted on a longer third-level subdomain under revolusioner.web.id, which is not consistent with the primary brand domains referenced in the page resources. Based on the domain structure, page content, and classification data, this site appears to be a brand-imitating page that may be intended to collect user information under the guise of customer support or account assistance.
Safety Assessment for xinewsdna-formindo.revolusioner.web.id
Multiple security signals indicate elevated risk at the time of this scan. The domain was flagged by 23 out of 91 security engines, and multiple web-classification providers categorized it as phishing or fraud-related. The page content also appears to imitate the DANA brand while being hosted on an unrelated domain, which is a common pattern associated with credential harvesting and other deceptive activity.
Additional context increases concern: the domain is very new at 33 days old, has no established traffic ranking, and includes a login-related endpoint among the flagged URLs. While one malware scan reported no directly flagged files and only generic detections on linked resources, that cleaner result is outweighed here by the broader multi-engine phishing consensus and the visible brand imitation. One blacklist database also listed the domain at the time of this scan.
Based on these findings, this website may pose potential risks to visitors.
Technical Description
The site was reachable over HTTPS with a valid Let's Encrypt certificate, and traffic appears to be served through Cloudflare infrastructure on IP address 188.114.97.2. The domain uses Cloudflare nameservers, while DNSSEC appears to be unsigned. A valid certificate may help encrypt traffic in transit, but it does not by itself indicate legitimacy.
From a technical-risk perspective, the main concerns are reputational rather than transport security: a very recently created domain, phishing-related detections across many security engines, and flagged internal resources including a login page and multiple locally hosted assets. The use of a subdomain on a broader host domain rather than a clearly official brand domain may also be a relevant trust concern.
Share your experience with this website. Was it safe? Did you encounter any issues?