item.ehay.com.login.secures-wr8wsvzt.construccionesjlfabririssas.com
Category: Phishing
To use full-featured product, you have to purchase a license for Combo Cleaner. Limited seven days free trial available. Combo Cleaner is owned and operated by RCS LT, the parent company of PCRisk.com.
Description of item.ehay.com.login.secures-wr8wsvzt.construccionesjlfabririssas.com
This domain appears to host a page designed to resemble an eBay account sign-in screen. The screenshot shows eBay branding, a login form, and third-party sign-in buttons, while the actual hostname is a long subdomain under construccionesjlfabririssas.com rather than an official eBay-owned domain. That mismatch strongly suggests the page may be attempting to imitate a legitimate e-commerce login experience rather than operating as an authorized eBay property.
Based on the domain structure and visible content, this does not appear to be a standalone business website for the underlying parent domain. Instead, it appears to be a credential-harvesting or brand-impersonation page using a deceptive subdomain format that places terms such as "item," "login," and a misspelled "ehay" before the real registered domain. The referenced assets also include resources loaded from genuine eBay-related domains, which may have been used to make the page look more convincing.
Safety Assessment for item.ehay.com.login.secures-wr8wsvzt.construccionesjlfabririssas.com
Multiple scan signals indicate elevated risk at the time of this scan. The URL was flagged by 21 out of 91 security engines, with many classifying it as phishing or otherwise malicious. In addition, one threat database listing was present, and the screenshot shows a login page that visually imitates eBay while being hosted on an unrelated domain. The domain name itself closely resembles eBay-related wording and may be a look-alike intended to mislead visitors into entering account credentials.
There is also a weaker secondary signal from mail-reputation data: the domain's IP address is listed on one DNS-based blocklist. On its own, that type of listing would not be strong evidence of website abuse, but in this case it appears alongside broad phishing detections, brand imitation, and a suspicious login workflow. Although the malware file scan did not report confirmed malicious files, its generic suspicious indicators do not outweigh the stronger phishing-related findings.
Based on these findings, this website may pose potential risks to visitors.
Technical Description
The site appears to be hosted on IP address 107.6.164.22 in Amsterdam, Netherlands, using an openresty/1.31.1.1 web server and nameservers ns1.tuhostingwb.com and ns2.tuhostingwb.com. The domain is about 3 years old, is not ranked in major traffic listings provided here, and DNSSEC is unsigned.
A notable technical concern is that SSL/TLS appears invalid or missing at the time of this scan, which is especially problematic for a page requesting account sign-in details. The combination of an unrelated parent domain, deceptive subdomain structure, missing or invalid HTTPS, and phishing detections across many security engines materially increases the likelihood that the page is not a legitimate login endpoint.
Share your experience with this website. Was it safe? Did you encounter any issues?