accounts.usnbweb[.]mobi
Category: Phishing
To use full-featured product, you have to purchase a license for Combo Cleaner. Limited seven days free trial available. Combo Cleaner is owned and operated by RCS LT, the parent company of PCRisk.com.
Description of accounts.usnbweb[.]mobi
The domain accounts.usnbweb[.]mobi appears to host a login page styled to resemble Binance, a well-known cryptocurrency trading platform. The visible page title, branding, and interface elements suggest that the site is presenting itself as an account access portal for Binance users rather than as an independent service.
Based on the domain structure, this does not appear to be an official Binance domain. The hostname uses a separate .mobi domain with an unrelated naming pattern, which may indicate that the page was set up to imitate a legitimate financial or cryptocurrency login experience. No clear evidence in the provided scan data identifies a legitimate operator for this domain.
Safety Assessment for accounts.usnbweb[.]mobi
Multiple security signals indicate elevated risk at the time of this scan. The domain was flagged by 19 out of 92 security engines, and several web-classification sources categorized it as phishing or fraud-related. In addition, the page visually presents a Binance-branded login screen while using a domain name that does not appear to belong to Binance, which strongly suggests it may be attempting to collect account credentials by impersonating a known service.
The domain is also very new, with an age of about 127 days, and it has no meaningful popularity ranking. While one malware scan did not detect malicious files, that result does not outweigh the broader phishing-related consensus from security engines, the blacklist listing, and the apparent brand imitation shown in the screenshot.
Based on these findings, this website may pose potential risks to visitors.
Technical Description
The site was reachable over HTTPS with a valid SSL/TLS certificate issued by TrustAsia Technologies, and the certificate was valid until 2026-07-28. It was served through TencentEdgeOne infrastructure, with the resolved IP address 43.152.186.225 and hosting geolocated to Paris, France. DNSSEC appears to be unsigned.
From a technical standpoint, the presence of HTTPS only indicates encrypted transport and should not be treated as proof of legitimacy. Additional concerns include the domain's recent registration date, lack of DNSSEC, phishing-related detections from multiple security engines, and a blacklist listing at the time of this scan.
Share your experience with this website. Was it safe? Did you encounter any issues?