mailbox-warhs73.public.builtwithrocket.new
Category: Phishing
To use full-featured product, you have to purchase a license for Combo Cleaner. Limited seven days free trial available. Combo Cleaner is owned and operated by RCS LT, the parent company of PCRisk.com.
Description of mailbox-warhs73.public.builtwithrocket.new
This domain appears to host a webmail-style interface branded as "MailBox," with folders such as Inbox, Sent, Drafts, Spam, and Trash, plus pages labeled "Security Shield" and "Webmail Login." Based on the screenshot and URL structure, it appears to be a browser-based email portal or a mock email environment built on a modern JavaScript framework. The presence of paths such as /webmail-login and /security-shield suggests the site may be designed to collect login interactions or simulate an email account workflow.
The domain itself is a subdomain under builtwithrocket.new rather than a standalone business domain, which may indicate it is hosted on a site-building or deployment platform. The page content shows a polished inbox dashboard with sample messages referencing business, finance, and account-security themes, including a message styled as a sign-in alert. Based on the available data, this setup appears more consistent with a themed webmail/login experience than with a conventional public business website.
Safety Assessment for mailbox-warhs73.public.builtwithrocket.new
Scan results indicate elevated risk at the time of analysis. The domain was flagged by 5 out of 89 security engines, with several classifying it as malicious or phishing-related. In addition, the published trust score provided with the scan is 19/100 and labels the site as phishing. While the malware file scan did not detect flagged files and several major threat databases were clean at the time of this scan, the combination of multiple engine detections and the page's email-login presentation materially increases concern.
The screenshot shows a webmail-themed interface on an uncommon subdomain, including a dedicated "Webmail Login" section and inbox content that references account statements and sign-in alerts. That presentation may be consistent with credential-harvesting or social-engineering use, especially because the domain is not associated with a recognizable mail provider and has no meaningful traffic ranking. The domain's IP address is also listed on one mail-reputation blocklist, which is a weaker signal than content-based phishing detections but still worth noting.
Based on these findings, this website may pose potential risks to visitors, particularly if it requests email credentials or other sensitive information.
Technical Description
The site uses a valid TLS certificate issued by Sectigo and is hosted behind AWS Global Accelerator, with Cloudflare nameservers configured. DNSSEC appears to be unsigned, which is not uncommon but does mean DNS responses do not benefit from that additional integrity layer. The observed asset paths suggest a Next.js-style application, and the page loads resources from related rocket.new infrastructure as well as a common font CDN.
From a security standpoint, the main concerns are reputational rather than transport-level: multiple security-engine detections, a phishing-oriented trust label in the scan context, and a mail-reputation blocklist listing on the IP. The certificate itself does not establish legitimacy, and the use of mainstream hosting/CDN infrastructure is compatible with both legitimate and abusive deployments.
Share your experience with this website. Was it safe? Did you encounter any issues?