rfefrgdgfddf.duckdns.org
Category: Phishing
To use full-featured product, you have to purchase a license for Combo Cleaner. Limited seven days free trial available. Combo Cleaner is owned and operated by RCS LT, the parent company of PCRisk.com.
Description of rfefrgdgfddf.duckdns.org
This domain appears to host a login page styled to resemble PostFinance's e-finance portal. The page title, meta description, visible branding, and linked assets all reference PostFinance and online banking functions such as account login, password entry, and user identification.
However, the actual domain is a DuckDNS subdomain rather than an official PostFinance web address. Based on the available page content and domain structure, the site does not appear to be operated by PostFinance itself and instead may be presenting a copy or imitation of a financial login interface.
The combination of banking-themed content, credential-entry fields, and third-party branding on an unrelated hostname is commonly associated with credential-harvesting pages. Based on the available data, this site appears to target users seeking access to PostFinance online banking services.
Safety Assessment for rfefrgdgfddf.duckdns.org
Multiple independent security signals indicate elevated risk at the time of this scan. The domain was flagged by 19 out of 91 security engines, with many classifying it as phishing or malicious, and it was also listed by a major threat database for social-engineering activity. In addition, another blacklist source reported a malicious-object listing, while the domain's IP address appeared on one mail-reputation blocklist; that DNS-based listing is a weaker signal on its own, but it adds to the overall caution here.
The page content further increases concern because it appears to imitate a financial login page for PostFinance while being hosted on an unrelated DuckDNS subdomain. That mismatch between the displayed brand and the actual hostname is a common sign of a look-alike credential collection page. The screenshot shows username, password, and identification fields, which may be intended to capture sensitive banking information from visitors.
Although the domain itself is old, the age of a dynamic DNS parent domain does not offset the stronger phishing indicators present in the page content and scan results. Based on these findings, this website may pose potential risks to visitors.
Technical Description
The site was reachable over HTTPS with a valid Let's Encrypt certificate that, at the time of this scan, was set to expire on 2026-10-14. It appears to be served by Apache from IP address 157.254.223.155, hosted by Vantiva USA Shared Services Inc. in Buffalo, United States. DNS uses DuckDNS nameservers, and DNSSEC appears to be unsigned.
From a security perspective, the presence of TLS should not be treated as evidence of legitimacy, since phishing pages commonly use valid certificates as well. The more notable concerns here are the use of a dynamic DNS subdomain for a banking-themed login page, the mismatch between the displayed PostFinance branding and the actual hostname, and the substantial number of phishing detections from security engines at the time of this scan.
Share your experience with this website. Was it safe? Did you encounter any issues?