clientlogin.eistee-mediart.de
Category: Phishing
To use full-featured product, you have to purchase a license for Combo Cleaner. Limited seven days free trial available. Combo Cleaner is owned and operated by RCS LT, the parent company of PCRisk.com.
Description of clientlogin.eistee-mediart.de
This subdomain appears to present a login page styled to resemble PayPal, with fields for email and password and branding elements associated with that payment platform. The hostname uses the subdomain label "clientlogin" under eistee-mediart.de rather than an official PayPal-owned domain, which suggests it may be intended to collect account credentials rather than provide a legitimate payment-service login.
Based on the page content and the classification data provided, the site appears to fall into the phishing/fraud category rather than functioning as a normal business, media, or informational website. The underlying parent domain is several years old, but this specific subdomain appears to be used for a narrowly focused credential-entry page.
Safety Assessment for clientlogin.eistee-mediart.de
Multiple independent security signals indicate elevated risk at the time of this scan. The URL was flagged by 19 out of 91 security engines, and multiple web-classification providers categorized it as phishing or fraud-related. In addition, a major threat database listed the page for social-engineering activity. The screenshot also shows a login form visually imitating PayPal while being hosted on a different domain, which may indicate an attempt to capture user credentials.
The malware scan did not detect malicious files in the small set of page resources that were checked, and no suspicious external links or iframes were identified in that scan. However, a clean file-level scan does not outweigh the stronger phishing indicators when the page itself appears to mimic a well-known financial brand on an unrelated domain.
Based on these findings, this website may pose potential risks to visitors, particularly anyone asked to enter account credentials or other sensitive information.
Technical Description
The site was reachable over HTTPS with a valid Let's Encrypt certificate that, at the time of this scan, was set to expire on 2026-09-20. DNSSEC appears to be enabled, which can help protect DNS integrity, and the domain uses nameservers associated with One.com. The server IP resolved to 46.30.213.97 with hosting infrastructure located in Copenhagen, Denmark.
From a technical perspective, the presence of valid TLS and signed DNS records does not by itself establish legitimacy; phishing pages commonly use standard hosting and valid certificates. The domain is relatively old at about 11 years, but the suspicious activity appears tied to this specific subdomain and page content rather than to domain age alone.
Share your experience with this website. Was it safe? Did you encounter any issues?