xioamigpscar.cheetahcar.shop
Category: Phishing
To use full-featured product, you have to purchase a license for Combo Cleaner. Limited seven days free trial available. Combo Cleaner is owned and operated by RCS LT, the parent company of PCRisk.com.
Description of xioamigpscar.cheetahcar.shop
This domain appears to present itself as a Xiaomi-branded GPS/car-tracking related website in Persian, with homepage content describing installation, setup, support, and features for a vehicle tracking application. The page references functions such as fast performance, local servers, fuel cut-off, and location tracking, suggesting a service tied to automotive GPS devices or fleet/vehicle monitoring.
However, the domain name itself does not appear to be an official Xiaomi domain and includes a misspelled brand-like string ("xioami" rather than "xiaomi") under a separate shop subdomain. Based on the visible content and structure, the site may be attempting to look like a brand-affiliated support or product page for Xiaomi-related tracking hardware, but the available ownership details do not clearly establish an official relationship with that brand.
Safety Assessment for xioamigpscar.cheetahcar.shop
Scan results indicate substantial risk signals at the time of this scan. The domain was flagged by 22 out of 91 security engines, with multiple detections describing phishing or malicious activity. In addition, major threat-database checks show listings for social-engineering and unwanted-software concerns, and another phishing database also lists the domain. The domain name closely resembles the Xiaomi brand while using a misspelled variant, which may indicate a look-alike setup intended to confuse visitors.
The malware crawl itself reported no individually flagged files, but it did attach a generic malicious label to the domain and many internal URLs. That kind of generic heuristic can be lower confidence on its own, but here it is outweighed by the broader multi-engine consensus and blacklist listings. The domain's IP address is also listed on one mail-reputation blocklist, which is a weaker signal than content-based phishing listings but still adds some caution.
Taken together, the combination of broad phishing detections, threat-database listings, invalid or missing SSL, and brand-resembling naming patterns suggests elevated risk. Based on these findings, this website may pose potential risks to visitors.
Technical Description
The site appears to be hosted on infrastructure associated with Hostiran Network in Tehran, Iran, resolving to IP address 5.144.130.187. DNSSEC is not enabled (unsigned), and the domain uses the nameservers ns1.hostiran.net and ns2.hostiran.net. The page structure and asset paths suggest a WordPress-based site using Elementor components.
A notable technical concern is that SSL/TLS appears invalid or missing at the time of this scan, which can affect confidentiality and authenticity for visitors. The domain is about 2 years old, which is older than many throwaway phishing domains, but age alone does not offset the stronger phishing and blacklist signals observed here.
Share your experience with this website. Was it safe? Did you encounter any issues?