mbox-onr1qc3bkkrfqp78sbmctstcdahkda5k.kind2932.de
Category: Phishing
To use full-featured product, you have to purchase a license for Combo Cleaner. Limited seven days free trial available. Combo Cleaner is owned and operated by RCS LT, the parent company of PCRisk.com.
Description of mbox-onr1qc3bkkrfqp78sbmctstcdahkda5k.kind2932.de
This domain appears to host a web page styled as an email login portal, with the page title "Aruba Webmail" and a screenshot showing an "Aruba Mail" sign-in form in Italian. The page asks for an email address and password and includes branding elements that resemble a legitimate webmail service, along with a prompt to access a document.
Safety Assessment for mbox-onr1qc3bkkrfqp78sbmctstcdahkda5k.kind2932.de
Multiple independent signals indicate elevated risk at the time of this scan. The domain was flagged by 16 out of 91 security engines, and multiple web-classification providers categorized it as phishing or fraud-related. In addition, the URL was listed by major threat databases for social-engineering activity, and another phishing-focused database also listed it. The page content itself appears to imitate a branded webmail login experience, which may be intended to collect account credentials from visitors.
There is also a weaker secondary signal showing the domain's IP address listed on one mail-reputation blocklist. While that type of listing alone would not prove harmful website activity, it adds to the overall caution when combined with the stronger phishing detections and the credential-harvesting appearance of the page. Based on these findings, this website may pose potential risks to visitors.
Technical Description
The site was reachable over HTTPS with a valid Let's Encrypt certificate that, at the time of this scan, was set to expire on 2026-11-06. It appears to be served by nginx from an IP address geolocated to Bella Vista, Panama, with hosting attributed to Panamaserver.com. The domain uses nameservers under the ui-dns.de / ui-dns.biz / ui-dns.com / ui-dns.org set.
DNSSEC appears to be unsigned, which means DNS responses may not benefit from that additional integrity layer. The scan also noted several internally referenced assets and one HTML page marked by a heuristic scanner as suspicious, although the stronger concern here comes from the broad phishing consensus across security engines and blacklist databases rather than from those generic heuristic flags alone.
Share your experience with this website. Was it safe? Did you encounter any issues?