nftbancusportal.pages.dev
Category: Phishing
To use full-featured product, you have to purchase a license for Combo Cleaner. Limited seven days free trial available. Combo Cleaner is owned and operated by RCS LT, the parent company of PCRisk.com.
Description of nftbancusportal.pages.dev
This domain appears to host a cryptocurrency-themed landing page branded as "BANC Token | Members." Based on the page title, on-page text, and screenshot, it presents itself as a token-claim portal for the BANC ecosystem, offering visitors the ability to "claim" BANC tokens through multiple blockchain networks including ETH/BSC, Solana, and TRON. The page also references assets hosted on bancus.io and uses common web resources such as Tailwind CSS, logo files, and embedded media thumbnails.
The site is served from a pages.dev subdomain, which indicates it is likely deployed through a static hosting platform rather than operating from a standalone branded domain. That setup can be used for legitimate prototypes and campaign pages, but it is also commonly used for short-lived promotional or wallet-interaction pages. Based on the available content, the operator appears to be presenting the site as related to a crypto token project, though the scan data does not independently verify any official relationship between this pages.dev subdomain and the Bancus-branded service referenced in the page assets.
Safety Assessment for nftbancusportal.pages.dev
This domain shows several notable risk indicators at the time of this scan. It was flagged by 13 out of 91 security engines, with the detections broadly classifying it as phishing-related rather than as a conventional malware host. The screenshot also shows a crypto-claim workflow encouraging users to connect or interact across multiple chains, which is a pattern often associated with wallet-draining or credential-harvesting campaigns when presented through unofficial landing pages.
At the same time, the malware scan did not identify malicious files in the small set of scanned resources, and the checked blacklist databases were reported clean at the time of review. Those clean results do not outweigh the multi-engine phishing consensus, but they do suggest the concern may relate more to deceptive page behavior, impersonation, or fraudulent wallet interaction than to downloadable malware payloads.
The use of a generic hosting subdomain instead of a primary branded domain, combined with the strong phishing consensus from multiple security engines and the token-claim framing, materially increases risk. Based on these findings, this website may pose potential risks to visitors.
Technical Description
The site is hosted behind Cloudflare infrastructure on IP address 172.66.47.122 and presents a valid TLS certificate issued by Google Trust Services, with expiry listed in August 2026. The web server is identified as Cloudflare, and the domain uses Cloudflare nameservers. DNSSEC appears to be unsigned at the time of this scan.
From a technical standpoint, the page looks like a lightweight hosted landing page rather than a full application, with a small number of scanned files and no flagged iframes. External resources include JavaScript files on the same host, media from bancus.io, and a workers.dev endpoint. While valid HTTPS is present, that only confirms encrypted transport and does not by itself establish legitimacy. The main technical concern here is not TLS weakness but the combination of hosted landing-page infrastructure and phishing-related detections.
Share your experience with this website. Was it safe? Did you encounter any issues?