cb.vault-secure.com
Category: Spyware And Malware
To use full-featured product, you have to purchase a license for Combo Cleaner. Limited seven days free trial available. Combo Cleaner is owned and operated by RCS LT, the parent company of PCRisk.com.
Description of cb.vault-secure.com
The domain cb.vault-secure.com appears to host a login page themed as a cryptocurrency account-access portal. Based on the screenshot, it presents itself as a "Sign in to Coinbase Vault" page and offers email entry along with passkey, Google, and Apple sign-in options. The page design suggests an attempt to resemble a financial or crypto custody login experience rather than a general informational website.
Based on the domain structure and page content, this does not appear to be an official primary domain for Coinbase. Instead, it appears to be a subdomain under vault-secure.com that references a well-known cryptocurrency brand in the page content. Multiple web-classification sources associate the site with phishing, fraud, or malware-related activity, while one category source labels it broadly under financial services, likely due to the login and account-access theme.
Safety Assessment for cb.vault-secure.com
This website shows multiple high-risk indicators at the time of this scan. It was flagged by 13 out of 91 security engines, and several web-classification providers categorized it as phishing, fraud, spyware, or malware-related. In addition, a major threat database listed the domain for social-engineering activity, which is a strong signal when assessing possible credential-harvesting pages.
The screenshot adds further concern because the page claims to be a "Coinbase Vault" sign-in screen while operating from cb.vault-secure.com rather than an official Coinbase domain. That resemblance may indicate a look-alike login page intended to collect account credentials or authentication details. The domain is also extremely new, with an age of 0 days and no established traffic ranking, which is commonly seen in short-lived phishing infrastructure.
Although the page-level malware scan did not detect malicious files in the limited content examined, that does not offset the stronger phishing indicators from multi-engine detections, blacklist data, and the visible brand-themed login prompt. Based on these findings, this website may pose potential risks to visitors.
Technical Description
The site uses a valid Let's Encrypt SSL certificate expiring on 2026-09-29, which means traffic may be encrypted in transit, but HTTPS alone does not indicate legitimacy. DNSSEC appears to be unsigned, the web server software was not identified, and the domain uses Cloudflare nameservers while resolving to an IP hosted by Prospero OOO in St Petersburg, Russia.
From an infrastructure perspective, the domain is newly registered and has a very short operating history, which may increase uncertainty. The combination of a fresh registration, unsigned DNSSEC, unknown server stack, and phishing-related detections suggests elevated technical risk at the time of this scan.
Share your experience with this website. Was it safe? Did you encounter any issues?