extranet.pb3.duckdns.org
Category: Phishing
To use full-featured product, you have to purchase a license for Combo Cleaner. Limited seven days free trial available. Combo Cleaner is owned and operated by RCS LT, the parent company of PCRisk.com.
Description of extranet.pb3.duckdns.org
The domain extranet.pb3.duckdns.org appears to be a subdomain hosted under DuckDNS, a dynamic DNS platform often used to publish temporary or self-managed services. Based on the screenshot, the page presents itself as a login portal in Portuguese and visually resembles an account-access page for a financial institution, including branding elements and a prompt to redeem loyalty points before signing in.
The content suggests the page is intended to collect account credentials such as CPF and password. However, the hostname itself does not appear to match an official corporate banking domain, and the use of a third-party dynamic DNS subdomain for a financial login page is unusual. Based on the available categories and page presentation, this site appears to be associated with credential-harvesting or phishing activity rather than a legitimate customer portal.
Safety Assessment for extranet.pb3.duckdns.org
Multiple independent signals indicate elevated risk at the time of this scan. The domain was flagged by 15 out of 91 security engines, and several web-classification sources categorized it as phishing, fraud, or proxy-related. In addition, major threat-database checks showed listings for social-engineering/phishing activity, which is a stronger signal than a generic heuristic alert. The screenshot also shows a banking-style login page asking for personal credentials, which may be consistent with an attempt to imitate a legitimate financial service.
There are a few weaker or mixed signals in the data: the malware scan reported no flagged files, and the generic suspicious-object label on the stylesheet reference is low-confidence on its own. However, those points are outweighed here by the broader multi-engine phishing consensus and the visible credential-collection interface. The domain's IP address is also listed on one mail-reputation blocklist, which may indicate reputation issues but is a secondary signal compared with the phishing listings.
Based on these findings, this website may pose potential risks to visitors.
Technical Description
The site uses a valid Let's Encrypt SSL certificate with an expiry in November 2026, which means the connection can be encrypted in transit, but HTTPS alone does not establish legitimacy. DNSSEC appears to be unsigned, and the hostname is a subdomain of duckdns.org rather than a dedicated corporate domain. The domain itself is old, but that age applies to the parent registration and does not necessarily establish trust for this specific subdomain.
The server resolves to IP address 15.235.30.84 and appears to be hosted in São Paulo, Brazil, with the web server software not identified in the scan data. From a security perspective, the most notable concern is not the TLS setup but the mismatch between the financial-login presentation and the dynamic DNS hosting pattern, alongside the phishing-related detections observed at the time of scanning.
Share your experience with this website. Was it safe? Did you encounter any issues?