xmidas.specialfors[.]com
Category: Phishing
To use full-featured product, you have to purchase a license for Combo Cleaner. Limited seven days free trial available. Combo Cleaner is owned and operated by RCS LT, the parent company of PCRisk.com.
Description of xmidas.specialfors[.]com
This domain appears to present itself as a promotional or event page related to Midasbuy and PUBG MOBILE, featuring in-game recharge rewards, redeemable items, and account-related actions such as sign-in and balance viewing. The page layout and branding shown in the screenshot suggest it is targeting players interested in mobile game top-ups, virtual currency, or limited-time gaming events.
Based on the domain structure, however, the site is hosted on a subdomain of specialfors.com rather than on a clearly recognizable primary domain associated with the branded service it references. That mismatch may indicate the page is unofficial, affiliate-driven, or designed to imitate a legitimate gaming payment or rewards portal. No clear operator identity is provided in the scan data, so ownership and authorization could not be independently confirmed from the available information.
Safety Assessment for xmidas.specialfors[.]com
The scan results show substantial concern at the time of this scan. The URL was flagged by 21 out of 91 security engines, with many classifying it as phishing or otherwise malicious. In addition, the domain is very new at roughly 93 days old, has no measurable popularity ranking, and uses branding associated with a well-known gaming payment platform and game title while being hosted on an unrelated parent domain. That combination is commonly associated with credential harvesting, fake reward pages, or deceptive promotional campaigns.
A separate malware file scan did not detect malicious files on the page at the time of analysis, and several blacklist databases did not list the domain. However, phishing pages often contain little or no malware payload and instead rely on social engineering, cloned branding, and login prompts to capture user credentials or payment details. The screenshot's use of recognizable game branding and an "Official Store" presentation on a non-official-looking domain increases the likelihood that visitors could be misled.
Based on these findings, this website may pose potential risks to visitors.
Technical Description
The site was served over HTTPS with a valid TLS certificate issued by a mainstream certificate authority, and it appears to be proxied through Cloudflare infrastructure with hosting resolved to an IP in Canada. The nameservers also point to Cloudflare, which is common for both legitimate and abusive sites and should not be treated as a trust signal by itself.
From a domain-security perspective, the domain is newly registered, DNSSEC is unsigned, and the site sits on a subdomain rather than a clearly established brand-owned domain. No malicious files, flagged external links, or iframes were identified in the provided page scan, but those findings do not offset the stronger phishing indicators present in the reputation data and branding mismatch.
Share your experience with this website. Was it safe? Did you encounter any issues?