login-botty[.]com
Category: Phishing
To use full-featured product, you have to purchase a license for Combo Cleaner. Limited seven days free trial available. Combo Cleaner is owned and operated by RCS LT, the parent company of PCRisk.com.
Description of login-botty[.]com
login-botty[.]com appears to present itself as the web presence for “Botty,” a cryptocurrency trading bot platform. Based on the page title, meta description, and homepage screenshot, the site markets automated crypto trading tools aimed at beginners and experienced users, with calls to start using the service for free and references to mobile app availability.
The homepage is in Russian and includes promotional graphics, testimonials, and navigation items such as reviews, how it works, platform information, calculator, FAQ, and contacts. The domain also references botty.com and includes links to social and analytics services, which suggests it may be positioned as a login or campaign-related domain associated with a broader crypto-trading brand rather than a standalone informational website.
Because the domain name uses a “login-” prefix rather than the apparent primary brand domain, it may function as a sign-in, landing, or acquisition page. Based on available data alone, the operator identity is not clearly established from the scan details provided.
Safety Assessment for login-botty[.]com
This domain shows several cautionary signals at the time of this scan. It was flagged by 5 out of 92 security engines, with multiple detections describing the site as phishing-related, while another scanner labeled it suspicious. In addition, one web-classification source categorized the domain as phishing. Although blacklist databases checked here did not list the domain, multi-engine phishing detections are a meaningful risk indicator, especially for a newly registered site.
The domain is only 58 days old, is not ranked among popular sites, and uses a name that closely resembles a login-oriented sub-brand or alternate entry point for “Botty.” That naming pattern may increase the possibility of credential harvesting or brand look-alike abuse, particularly because the page promotes financial activity involving cryptocurrency, a sector frequently targeted by impersonation and account-theft campaigns.
At the same time, the malware file scan did not identify flagged files, and the checked blacklist sources were clean at the time of this scan. Even so, phishing pages often contain little or no overt malware, so a clean file scan does not materially offset the phishing-related detections. Based on these findings, this website may pose potential risks to visitors.
Technical Description
The site is served through Cloudflare infrastructure and resolves to an IP associated with Cloudflare in Toronto, Canada. It uses a valid Let's Encrypt SSL certificate, which indicates encrypted transport is present, though the specific TLS protocol details were not provided in the scan. The domain uses Cloudflare nameservers and has DNSSEC listed as unsigned.
From a security posture perspective, the main concerns are not certificate validity but domain age, phishing-related detections from multiple security engines, and the use of a login-themed domain name for a crypto-related service. The site also loads external resources such as tag-management content and references several third-party domains. DNSSEC not being enabled is common and not inherently suspicious, but it does mean there is no added DNS integrity protection at the domain level.
Share your experience with this website. Was it safe? Did you encounter any issues?