oeruexta.com
Category: Phishing
To use full-featured product, you have to purchase a license for Combo Cleaner. Limited seven days free trial available. Combo Cleaner is owned and operated by RCS LT, the parent company of PCRisk.com.
Description of oeruexta.com
oeruexta.com appears to present itself as a cryptocurrency trading platform. Based on the screenshot, it uses exchange-style marketing language such as "A Better Way to Exchange" and displays trading-related navigation items including spot trading, leverage trading, options trading, ETFs, and account management features. The page also shows crypto and commodity-style price tiles, suggesting that it is attempting to resemble an online financial trading or digital-asset exchange service.
The domain name itself does not appear to match a widely recognized exchange brand, while the page design prominently references "BYBIT," which may indicate that the site is attempting to imitate or borrow the branding of an established cryptocurrency platform. The site is hosted behind a content-delivery and reverse-proxy service and uses a basic homepage title of "Home," which provides limited independent business identification. Based on available data, the operator is not clearly identified in the scan details provided.
Safety Assessment for oeruexta.com
This website shows multiple risk indicators at the time of this scan. It was flagged by 17 out of 91 security engines, with many of those detections classifying it as phishing or otherwise malicious. In addition, the domain is extremely new at only 2 days old, has no established traffic ranking, and the screenshot suggests that it may be presenting itself as a well-known cryptocurrency exchange despite using an unrelated domain name. That combination is commonly associated with credential-harvesting or account-theft campaigns.
Blacklist and reputation data were mixed rather than fully clean. Major content-malice databases in the provided scan did not all report a block, but the domain or its infrastructure was listed by a generic malicious-object source, and the domain's IP address was also listed on one mail-reputation blocklist. A DNSBL listing alone would be a weak signal, but in this case it appears alongside substantial multi-engine phishing detections and a very recent registration, which increases concern.
The malware page scan itself did not detect malicious files in the small set of resources examined, but that does not outweigh the broader phishing indicators. Based on these findings, this website may pose potential risks to visitors.
Technical Description
The site uses a valid Let's Encrypt SSL certificate expiring on 2026-10-08 and is served through Cloudflare infrastructure on IP address 104.18.20.48, with hosting geolocated to Toronto, Canada based on available data. Nameservers are set to Dynadot-managed DNS, and DNSSEC appears to be unsigned.
From a technical standpoint, the presence of HTTPS is a basic transport-security feature and should not be treated as proof of legitimacy. The scan found only a small number of static assets and no flagged files, but the combination of a newly registered domain, hidden origin behind reverse-proxy infrastructure, unsigned DNSSEC, and strong phishing detections from multiple security engines may warrant caution.
Share your experience with this website. Was it safe? Did you encounter any issues?