home-page-btimart-auth-sso.webflow[.]io
Category: Phishing
To use full-featured product, you have to purchase a license for Combo Cleaner. Limited seven days free trial available. Combo Cleaner is owned and operated by RCS LT, the parent company of PCRisk.com.
Quttera Web Malware Removal is a paid subscription service. Pricing, plans, and trial availability are set by Quttera. Quttera is operated by Quttera Ltd, an independent third-party company unrelated to RCS LT. PCRisk.com may earn a referral commission when users sign up through this link.
Description of home-page-btimart-auth-sso.webflow[.]io
The scanned page appears to be a Webflow-hosted site designed to resemble a cryptocurrency trading and account-access portal for BitMart. Its title, metadata, and on-page branding reference crypto trading, digital assets, market data, and account login functionality, suggesting that it is presenting itself as a gateway for users to sign in and manage cryptocurrency-related activity.
However, the domain itself is a subdomain on webflow.io rather than an official brand-owned domain, and the naming pattern "home-page-btimart-auth-sso" strongly suggests an attempt to imitate a branded single sign-on or authentication page. Based on the screenshot and metadata, the page appears to mimic the look and messaging of a cryptocurrency exchange rather than operating as an independent informational site.
The underlying webflow.io domain is long-established and operated through a mainstream website-building platform, but that does not by itself validate the legitimacy of this specific subpage. In this case, the content appears to be focused on cryptocurrency account access and may be targeting users who expect to reach an official BitMart login experience.
Safety Assessment for home-page-btimart-auth-sso.webflow[.]io
Multiple risk indicators were present at the time of this scan. The URL was categorized by several web-classification providers as phishing or fraud-related, and 21 out of 92 security engines flagged it. That level of multi-engine agreement is a strong warning sign compared with isolated or purely heuristic detections. In addition, blacklist data showed listings in some threat databases at the time of review.
The page also appears to imitate the BitMart brand while being hosted on a third-party webflow.io subdomain rather than an apparent official BitMart domain. The wording in the domain name references authentication and single sign-on, and the screenshot shows BitMart branding and exchange-style interface elements. This resemblance may indicate a look-alike page intended to capture credentials or other sensitive information from users expecting the legitimate service.
A separate malware scan mainly reported generic suspicious-object findings on hosted assets, which on their own would be lower-confidence signals. However, in this case those weaker indicators are outweighed by the broader phishing classifications and the high number of security-engine detections. Based on these findings, this website may pose potential risks to visitors.
Technical Description
The site was served over HTTPS with a valid TLS certificate issued by a mainstream certificate authority, and the observed infrastructure was behind Cloudflare with an IP address geolocated to Canada at the time of the scan. The nameservers also point to Cloudflare, indicating use of a common CDN and reverse-proxy setup. DNSSEC appeared to be unsigned.
From a technical perspective, the use of valid HTTPS and reputable hosting infrastructure does not by itself establish legitimacy, as phishing pages commonly use mainstream platforms and CDN protection. The flagged resources were standard Webflow-hosted CSS and JavaScript assets, and the more meaningful concern is the apparent brand imitation and phishing-related detections rather than any confirmed malware payload in the page assets.
Share your experience with this website. Was it safe? Did you encounter any issues?