2db39ur9.bndcy0h.com
Category: Phishing
To use full-featured product, you have to purchase a license for Combo Cleaner. Limited seven days free trial available. Combo Cleaner is owned and operated by RCS LT, the parent company of PCRisk.com.
Description of 2db39ur9.bndcy0h.com
This domain appears to host a website presenting itself as an "imToken official website" for a cryptocurrency wallet focused on Ethereum, Bitcoin, and other digital assets. The page promotes wallet downloads, including an Android APK, and uses branding and marketing language associated with digital asset management services.
Based on the screenshot and metadata, the site appears to target users looking for a crypto wallet application rather than offering general informational content. The domain name itself is a random-looking subdomain under bndcy0h.com and does not appear to match the branding shown on the page, which may indicate the site is not operated through an obvious official brand domain.
No clear operator identity is visible from the provided scan data beyond the branding shown on the page. In practical terms, this appears to be a cryptocurrency-related landing page that may be attempting to attract users searching for the imToken wallet or its download links.
Safety Assessment for 2db39ur9.bndcy0h.com
The scan results show notable risk indicators at the time of this scan. The domain was flagged by 17 out of 91 security engines, with many of those detections classifying it as phishing or otherwise malicious. In addition, the page presents itself as an official cryptocurrency wallet site while using a random-looking domain that does not appear to align with the displayed brand, which may indicate brand impersonation or a look-alike setup.
Other signals add to the caution. The domain is very new at 14 days old, has no established traffic ranking, and promotes an APK download for a crypto wallet, which is a common lure pattern in credential theft and malware-delivery campaigns. Although the malware file scan did not detect flagged files and major content-focused threat databases were clean at the time of this scan, the domain's IP address is listed on one mail-reputation blocklist, which is a weaker but still relevant cautionary signal.
Taken together, the multi-engine phishing consensus, the mismatch between the displayed brand and the domain, and the very recent registration materially increase risk. Based on these findings, this website may pose potential risks to visitors.
Technical Description
The site uses a valid Let's Encrypt SSL certificate that was active at the time of the scan, and it is served over nginx from a Microsoft Azure cloud IP located in Hong Kong. A valid certificate helps encrypt traffic in transit, but it does not by itself verify that the site is legitimate.
From a domain-security perspective, the registration is very recent, DNSSEC appears to be unsigned, and the infrastructure uses cloud hosting with Cloud DNS nameservers. This combination is common for both legitimate short-lived deployments and abusive campaigns, so the stronger concern here comes from the reputation signals and page behavior rather than the hosting stack alone.
Share your experience with this website. Was it safe? Did you encounter any issues?