signin.broker
Category: Phishing
To use full-featured product, you have to purchase a license for Combo Cleaner. Limited seven days free trial available. Combo Cleaner is owned and operated by RCS LT, the parent company of PCRisk.com.
Description of signin.broker
signin.broker appears to be a subdomain under the .broker top-level domain, which suggests a possible connection to brokerage, financial services, account access, or login-related functionality. The specific hostname "signin" commonly indicates a sign-in portal intended for user authentication rather than a general informational website.
Based on the available scan context, the site does not appear to have an established public web presence or measurable popularity, as it is not ranked in major traffic lists. No clear business identity, publisher details, or visible category metadata were provided in the scan results, so the operator cannot be confidently identified from the available data alone.
Safety Assessment for signin.broker
Multiple security signals indicate elevated risk at the time of this scan. The domain was flagged by 17 out of 91 security engines, with many of those detections classifying it as phishing-related. In addition, it was listed by a major threat database for social-engineering activity, which is a stronger indicator than a generic heuristic alone. Although one malware scan reported no flagged files, that clean result does not outweigh the broader multi-engine phishing consensus.
Blacklist data also showed additional concerns. Beyond the social-engineering listing, another threat database entry indicated a generic malicious classification, and the domain's IP address was listed on one mail-reputation blocklist. That DNS-based listing is a weaker signal than phishing detections and may relate to IP reputation rather than website content, but it still adds some caution to the overall picture.
The domain is relatively new in practical terms, has no visible traffic ranking, and uses a login-themed hostname that could plausibly be used to collect credentials. Based on these findings, this website may pose potential risks to visitors.
Technical Description
The site presented a valid SSL/TLS certificate issued by a mainstream certificate authority, with expiry shown as 2026-10-23. A valid certificate helps encrypt traffic in transit, but it should not be treated as proof of legitimacy because phishing pages commonly also use HTTPS. DNSSEC appears to be unsigned, so there is no additional DNS integrity protection indicated in the scan data.
Infrastructure details suggest the domain is routed through Cloudflare nameservers and web-serving infrastructure, while the reported hosting points to Hoxhunt Oy in Helsinki, Finland. The server IP was 212.104.128.3 at the time of the scan. No malicious files, external links, or iframes were identified by the page-level malware scan, but the broader reputation data still indicates notable phishing-related concerns.
Share your experience with this website. Was it safe? Did you encounter any issues?