commerzbank.de-service[.]pw
Category: Phishing
To use full-featured product, you have to purchase a license for Combo Cleaner. Limited seven days free trial available. Combo Cleaner is owned and operated by RCS LT, the parent company of PCRisk.com.
Description of commerzbank.de-service[.]pw
The domain commerzbank.de-service[.]pw appears to present itself as a German banking website using Commerzbank branding, navigation labels, and page structure. The screenshot shows financial-service sections such as accounts, cards, investing, financing, insurance, and login, which suggests the site is attempting to resemble an online banking or financial-services portal aimed at German-speaking users.
Based on the domain structure, this does not appear to be an official Commerzbank domain. Instead, it uses the well-known bank name inside a longer third-level string under the .pw extension, which may be intended to make the address look familiar at a glance. The linked paths and referenced assets also imitate the layout and content organization of a large banking website, including legal notices, contact pages, and login-related sections.
No evidence in the provided scan indicates that this is an independent legitimate business with its own distinct brand. Based on the available data, the site appears to be a look-alike financial website that may be attempting to borrow the identity and trust signals of Commerzbank.
Safety Assessment for commerzbank.de-service[.]pw
This domain shows multiple high-risk indicators at the time of the scan. It was flagged by 12 out of 92 security engines, with several classifying it as phishing, malicious, or malware-related. In addition, the domain closely resembles commerzbank.de and may be a look-alike intended to imitate the legitimate banking brand while using a different domain structure and extension.
The domain is also extremely new, with a registration age of only 6 days, no Tranco ranking, and additional red flags noted in the similarity check. Although some blacklist databases and malware scans did not report active payloads at the time of this scan, that does not outweigh the stronger phishing-style indicators: the brand-like domain naming pattern, the banking-themed content, the login path, and the multi-engine detections.
Because this site appears to imitate a major financial institution on a newly registered, unrelated domain, visitors should treat it with a high degree of caution. Based on these findings, this website may pose potential risks to visitors.
Technical Description
The site was reachable over HTTPS with a valid Let's Encrypt certificate, hosted behind Cloudflare infrastructure and served by nginx/1.22.1 from IP address 104.21.81.63. The presence of TLS only indicates encrypted transport and should not be interpreted as proof of legitimacy. DNSSEC appears to be unsigned, and the domain uses Cloudflare nameservers.
From an infrastructure perspective, the setup looks lightweight and recently deployed. The domain was registered very recently through CNOBIN INFORMATION TECHNOLOGY LIMITED, which can be a concern when combined with a banking look-alike presentation and phishing-related detections. The scan data also notes no MX records, which may be another weak legitimacy signal for a site presenting itself as a major financial institution.
Share your experience with this website. Was it safe? Did you encounter any issues?