events.pb3.duckdns.org
Category: Phishing
To use full-featured product, you have to purchase a license for Combo Cleaner. Limited seven days free trial available. Combo Cleaner is owned and operated by RCS LT, the parent company of PCRisk.com.
Description of events.pb3.duckdns.org
This domain appears to host a login page presented in Portuguese and visually branded as a financial-services portal. The screenshot shows references to account access, reward-point redemption, CPF login, password entry, and a branded interface that resembles an online banking or investment account sign-in experience aimed at Brazilian users.
Based on the subdomain structure under duckdns.org, the site does not appear to be operating from an official corporate domain for the brand shown on the page. DuckDNS is commonly used for dynamic DNS hosting, which can support legitimate personal projects but is also frequently used for temporary or disposable deployments. In this case, the page appears to be set up to collect account credentials rather than to provide a full public-facing corporate website.
Safety Assessment for events.pb3.duckdns.org
Multiple security signals indicate elevated risk at the time of this scan. The domain was flagged by 11 out of 91 security engines, with the detections broadly classifying it as phishing or malicious. In addition, one threat database listing was present, and the domain's IP address was listed on one mail-reputation blocklist. While a separate malware scan reported no directly flagged files, it did note a low-confidence generic suspicious pattern on the domain and a referenced stylesheet URL.
The page content itself also raises concern. The screenshot shows a login form that appears to imitate BTG Pactual branding while being hosted on a duckdns.org subdomain rather than what would typically be expected for an official financial institution login. That mismatch between the displayed brand and the hosting domain may indicate a look-alike credential-harvesting page. Financial login pages on unrelated dynamic DNS subdomains warrant extra caution, even when HTTPS is present.
Based on these findings, this website may pose potential risks to visitors.
Technical Description
The site presented a valid Let's Encrypt SSL certificate expiring in November 2026, which means the connection appears to be encrypted in transit. However, HTTPS alone does not verify that the operator is legitimate. The server was hosted on IP address 15.235.30.84 in São Paulo, Brazil, with the web server software and protocol details not identified in the scan results.
The domain is relatively old at about 13 years, but that age applies to the duckdns.org parent registration context and does not by itself establish trust for this specific subdomain deployment. DNSSEC appears to be unsigned, and the use of a dynamic DNS namespace may make the host easier to repoint or rotate. Combined with the phishing-related detections and brand-mismatch concerns, the technical profile suggests caution at the time of this scan.
Share your experience with this website. Was it safe? Did you encounter any issues?