postfinance[.]top
Category: Suspicious, Newly Registered
To use full-featured product, you have to purchase a license for Combo Cleaner. Limited seven days free trial available. Combo Cleaner is owned and operated by RCS LT, the parent company of PCRisk.com.
Description of postfinance[.]top
The domain postfinance[.]top appears to present itself as an online banking login page for PostFinance, using the page title "E-finance login | PostFinance" and branding elements associated with that financial institution. The screenshot shows a German-language sign-in form requesting an online banking number, password, and phone number, which suggests the page is intended to imitate a digital banking access portal rather than provide independent informational content.
Based on the domain name and page content, this site does not appear to be the primary official PostFinance web domain. The page also references assets and domains associated with the legitimate brand, which may indicate an attempt to resemble the real service closely. Given the financial-login theme and the use of a newly registered .top domain, the website appears to be positioned as a banking-related portal rather than a standalone business or media site.
Safety Assessment for postfinance[.]top
Several risk indicators are present in this scan. The domain was flagged by 12 out of 91 security engines, and multiple web-classification providers categorized it as phishing, fraud, or suspicious. The page content closely resembles a PostFinance login experience while operating from postfinance[.]top rather than the brand's expected primary domain, which may indicate a look-alike website intended to capture user credentials.
Additional context increases concern: the domain is only 2 days old, has no established traffic ranking, and uses a financial-login theme that requests sensitive information. Although the malware scan did not detect malicious files at the time of analysis and some blacklist sources were clean, phishing pages often contain little or no malware payload and instead focus on credential harvesting. Based on these findings, this website may pose potential risks to visitors.
Technical Description
The site was reachable over HTTPS with a valid Let's Encrypt certificate expiring on 2026-08-02. It appears to be served by nginx from an IP hosted by ServerMania in the Netherlands. DNSSEC is not enabled, and the domain uses dnspodsag.com nameservers. A valid certificate indicates encrypted transport, but it does not by itself confirm legitimacy.
From a technical risk perspective, the strongest concerns are not malware-related but contextual: a very newly registered domain, an unsigned DNS configuration, and branding that appears to imitate a financial institution's login portal. The malware scan reported 0 flagged files out of 34 scanned at the time of this scan, which may suggest the page is focused on social engineering rather than delivering malicious code.
Share your experience with this website. Was it safe? Did you encounter any issues?