mail.sywsywml.rumahsakit.de
Category: Phishing
To use full-featured product, you have to purchase a license for Combo Cleaner. Limited seven days free trial available. Combo Cleaner is owned and operated by RCS LT, the parent company of PCRisk.com.
Description of mail.sywsywml.rumahsakit.de
This subdomain appears to host a page themed around PUBG MOBILE and in-game rewards. The page title is "PUBG MOBILE EVENT," and the screenshot shows a reward or redemption-style interface referencing Midasbuy, token points, and game items such as materials, helmets, and cosmetic sets. Based on the visible content, the page appears designed to attract players with offers of free or discounted in-game items.
The domain itself, mail.sywsywml.rumahsakit.de, does not appear to be an official PUBG MOBILE or Midasbuy web address. The structure looks like a nested subdomain under rumahsakit.de rather than a brand-owned gaming domain, which may be inconsistent with the branding shown on the page. Available data does not identify a clear legitimate operator, and the hosting appears to be provided through infrastructure in Indonesia.
Safety Assessment for mail.sywsywml.rumahsakit.de
This website shows multiple risk indicators at the time of this scan. It was flagged by 20 out of 91 security engines, with many of those detections classifying it as phishing. In addition, one threat database listing was present, and the domain's IP address was listed on one mail-reputation blocklist. While DNS-based mail-reputation listings are a weaker signal than direct malware or phishing detections, the broader multi-engine consensus here is a more significant concern.
The page content also raises credibility issues. The screenshot presents PUBG MOBILE and Midasbuy branding on a domain that does not appear to be an official brand domain, which may indicate brand impersonation or a credential-harvesting lure. Supporting scan artifacts include numerous flagged internal resources and filenames referencing login flows and major platform branding, which can be consistent with phishing-kit style deployment. Although one malware scan reported no flagged files, it also associated the domain and many linked resources with a generic malicious-object heuristic.
Based on these findings, this website may pose potential risks to visitors.
Technical Description
The site was reachable over HTTPS with a valid Let's Encrypt certificate that, at the time of this scan, was set to expire on 2026-10-14. It appears to be served by Apache from IP address 103.52.114.215, hosted by PT. Cloud Hosting Indonesia in Cicurug, Indonesia. The domain uses Cloudflare nameservers, while DNSSEC appears to be unsigned.
From a security perspective, the presence of a valid TLS certificate only indicates encrypted transport and does not by itself establish legitimacy. Additional concerns include the unusual multi-level subdomain structure, unknown WHOIS age and registrar details, and the concentration of phishing-related detections across security engines.
Share your experience with this website. Was it safe? Did you encounter any issues?