9000-firebase-storage-1781018389150.cluster-r7kbxfo3fnev2vskbkhhphetq6.cloudworkstations.dev
Category: Phishing
To use full-featured product, you have to purchase a license for Combo Cleaner. Limited seven days free trial available. Combo Cleaner is owned and operated by RCS LT, the parent company of PCRisk.com.
Description of 9000-firebase-storage-1781018389150.cluster-r7kbxfo3fnev2vskbkhhphetq6.cloudworkstations.dev
This domain appears to be a hosted page on the cloudworkstations.dev platform, using a long autogenerated subdomain rather than a branded standalone website. Based on the page title and screenshot, it presents a very simple "Mail" login form asking for an email address and password, with no visible company branding, legal information, or supporting site content.
The domain structure suggests it may be operated through a cloud-hosted development or workspace environment rather than by a recognizable public-facing organization. In the screenshot, the page functions as a generic credential-entry portal, which may be intended to imitate a webmail sign-in experience. Based on the available content, it does not appear to represent a full email service website with identifiable ownership or normal account-support pages.
Safety Assessment for 9000-firebase-storage-1781018389150.cluster-r7kbxfo3fnev2vskbkhhphetq6.cloudworkstations.dev
Multiple security engines flagged this URL at the time of the scan, with 11 out of 91 detections and several classifying it as phishing or otherwise malicious. The screenshot also shows a bare email-and-password login page with the generic title "Mail," which is a pattern commonly associated with credential-harvesting pages when no clear service identity, branding, or trust signals are present.
Blacklist and threat-database results were mixed at the time of the scan. Major content-malice checks shown here did not detect a threat, but the domain's IP address was listed on one mail-reputation blocklist, which is a weaker cautionary signal rather than direct proof about the webpage itself. The malware scan summary did not identify flagged files, but that does not outweigh the multi-engine phishing detections and the suspicious login-only presentation.
Given the combination of repeated phishing classifications, the extremely minimal login form, and the lack of visible legitimate service context, this website may pose potential risks to visitors at the time of this scan.
Technical Description
The site was reachable over HTTPS with a valid TLS certificate issued by Google Trust Services, expiring in September 2026. It appears to be hosted on Google Cloud at IP address 34.49.107.158 and served by nginx/1.26.3 from Kansas City, United States. The domain uses Google-managed nameservers.
DNSSEC appears to be unsigned, which is not uncommon but does mean DNS responses do not benefit from that additional integrity layer. From a technical standpoint, the presence of valid SSL should not be treated as a trust indicator by itself, since phishing pages also commonly use legitimate certificates and reputable cloud hosting.
Share your experience with this website. Was it safe? Did you encounter any issues?