9000-firebase-ree-1781589806336.cluster-l2bgochoazbomqgfmlhuvdvgiy.cloudworkstations.dev
Category: Information Technology, Malicious
To use full-featured product, you have to purchase a license for Combo Cleaner. Limited seven days free trial available. Combo Cleaner is owned and operated by RCS LT, the parent company of PCRisk.com.
Description of 9000-firebase-ree-1781589806336.cluster-l2bgochoazbomqgfmlhuvdvgiy.cloudworkstations.dev
This domain appears to be hosted on a cloud development subdomain under cloudworkstations.dev, which is commonly associated with temporary or project-specific web deployments rather than a standalone branded public website. The page title is simply "Mail," and the screenshot shows a minimal login form requesting an email address and password, with no visible company branding, legal information, or service explanation.
Based on the domain structure and page content, the site may be presenting itself as a generic webmail or account-access portal. However, there is no clear indication of who operates it, what organization it belongs to, or what legitimate service it is meant to support. The broad categorization data also associates the domain with information technology and fraud-related classifications rather than a recognized consumer mail provider.
Safety Assessment for 9000-firebase-ree-1781589806336.cluster-l2bgochoazbomqgfmlhuvdvgiy.cloudworkstations.dev
Multiple scan signals indicate elevated risk at the time of this scan. The domain was flagged by 17 out of 91 security engines, with many of those detections describing phishing, fraud, malware, or other malicious behavior. In addition, several web-classification sources categorized it as phishing-related. The screenshot reinforces that concern because it shows a generic email login page on an unrelated cloud-hosted subdomain, without visible branding or context that would help verify the legitimacy of the credential request.
Blacklist and reputation data were mixed rather than fully clean. Major content-malice checks shown here did not report a listing, but the domain's IP address is listed on one mail-reputation blocklist, and one additional blacklist source reported a generic malicious-object listing. While a mail-reputation listing alone would be a weak signal, it adds to the overall concern when combined with broad multi-engine phishing detections and a credential-harvesting style page.
The domain itself is not newly registered, which slightly reduces uncertainty, but age alone does not outweigh the concentration of phishing-related detections and the suspicious login-only presentation. Based on these findings, this website may pose potential risks to visitors.
Technical Description
The site uses a valid SSL/TLS certificate issued by a mainstream certificate provider, hosted on Google Cloud infrastructure at IP address 34.54.228.187, and served by nginx/1.26.3 from Kansas City, United States. The certificate validity suggests encrypted transport is in place, but HTTPS alone does not verify the trustworthiness of the page's purpose or operator.
DNSSEC appears to be unsigned, which is common but means DNS responses do not benefit from that additional integrity layer. The domain is a long cloud-hosted subdomain rather than a clearly branded primary domain, and the combination of generic hosting, minimal page content, and a credential-entry form may be operationally consistent with disposable phishing infrastructure.
Share your experience with this website. Was it safe? Did you encounter any issues?