hotdoc-reimbursements[.]com
Category: Phishing
To use full-featured product, you have to purchase a license for Combo Cleaner. Limited seven days free trial available. Combo Cleaner is owned and operated by RCS LT, the parent company of PCRisk.com.
Description of hotdoc-reimbursements[.]com
The domain hotdoc-reimbursements[.]com appears to be a newly registered website that references HotDoc, an Australian healthcare appointment platform, based on the domain name and the presence of a link to www.hotdoc.com.au. The wording "reimbursements" suggests the site may be presenting itself as a claims, refund, or payment-related portal connected to healthcare administration or patient billing workflows.
Based on the available scan data, this does not appear to be an established high-traffic web property, as it is not ranked among widely visited domains and was registered very recently. The infrastructure looks minimal, with a small number of scanned files and basic static assets, which may indicate a simple landing page or lightweight web application rather than a mature public-facing service.
Safety Assessment for hotdoc-reimbursements[.]com
This domain shows several cautionary indicators at the time of this scan. It was flagged by 2 out of 91 security engines, while malware scanning of the retrieved files did not detect malicious code and blacklist checks were largely clean. That mixed picture means there is not broad technical confirmation of malware, but there are still enough signals to warrant caution.
A more significant concern is that the domain is brand-referential and closely tied in wording to the known HotDoc brand while using a separate domain name. Combined with the domain age of 0 days, lack of established traffic history, and reimbursement-themed wording that could be used in payment or account-related lures, the site may be a look-alike intended to create trust through brand association. Even though no threats were detected in the downloaded files at the time of this scan, newly created look-alike domains can present elevated risk before broader detection coverage develops.
Based on these findings, this website may pose potential risks to visitors.
Technical Description
The site is using a valid Let's Encrypt SSL certificate expiring on 2026-08-01 and is hosted on an nginx/1.24.0 (Ubuntu) server at IP address 185.242.3.79, associated with hosting in Frankfurt am Main, Germany. The domain uses Dynadot nameservers and DNSSEC appears to be unsigned.
From a technical standpoint, the scan observed only a small set of files and no flagged malware artifacts, suspicious iframes, or flagged outbound links. However, the domain's extremely recent registration, unsigned DNSSEC status, unknown protocol details, and generic hosting setup provide limited trust signals on their own.
Share your experience with this website. Was it safe? Did you encounter any issues?