login.my.gov.au-taxstatement26.de5.net
Category: Phishing
To use full-featured product, you have to purchase a license for Combo Cleaner. Limited seven days free trial available. Combo Cleaner is owned and operated by RCS LT, the parent company of PCRisk.com.
Description of login.my.gov.au-taxstatement26.de5.net
The domain login.my.gov.au-taxstatement26.de5.net appears to be a subdomain hosted under de5.net rather than an official Australian government domain. Its naming pattern references "login.my.gov.au" and "tax statement," which suggests it may be attempting to resemble an authentication or tax-related portal associated with Australian public services. Based on the domain structure alone, it does not appear to be operated from the official gov.au namespace.
Technical indicators suggest the page is hosted on infrastructure associated with a common web-hosting platform and uses a valid TLS certificate. The presence of references to GitHub-related status and help pages in the extracted links may indicate reused template content, embedded assets, or hosting-related artifacts rather than a clear statement of ownership. Based on the available data, the site appears to present itself as a login-themed page rather than a transparent, independently branded website.
Safety Assessment for login.my.gov.au-taxstatement26.de5.net
Several security signals indicate elevated risk at the time of this scan. The domain was flagged by 8 out of 91 security engines, with multiple detections describing the page as phishing or malicious. In addition, the domain's IP address is listed on one mail-reputation blocklist, which is a weaker signal than direct phishing detections but still adds some caution. Although some blacklist and malware-scan sources did not detect active malicious files, that does not outweigh the broader multi-engine phishing consensus in this case.
The domain name closely resembles an Australian government login address and may be a look-alike intended to capture user credentials or sensitive tax-related information. That naming pattern is a significant concern even aside from the engine detections, because legitimate government services would typically use an official government-controlled domain. The domain is also not ranked for notable traffic, which may be consistent with a low-visibility or recently deployed campaign.
Following a manual review by the PCRisk team, the published trust score has been adjusted to reflect additional context. Based on these findings, this website may pose potential risks to visitors.
Technical Description
The site presents a valid Let's Encrypt SSL certificate expiring on 2026-10-25 and DNSSEC appears to be enabled, which are positive infrastructure features but do not by themselves establish legitimacy. It is hosted on GitHub-associated infrastructure at IP address 185.199.111.153, with the web server identified as GitHub.com and nameservers NS7.DNSHE.COM and NS8.DNSHE.COM.
From a security perspective, the main concern is not the TLS setup but the domain naming pattern and reputation signals. The use of a government-themed login string on a third-party subdomain, combined with multiple phishing-related detections, may indicate deceptive use of otherwise standard hosting and certificate services.
Share your experience with this website. Was it safe? Did you encounter any issues?