uz3480.craftum[.]io
Category: Phishing And Fraud
To use full-featured product, you have to purchase a license for Combo Cleaner. Limited seven days free trial available. Combo Cleaner is owned and operated by RCS LT, the parent company of PCRisk.com.
Quttera Web Malware Removal is a paid subscription service. Pricing, plans, and trial availability are set by Quttera. Quttera is operated by Quttera Ltd, an independent third-party company unrelated to RCS LT. PCRisk.com may earn a referral commission when users sign up through this link.
Description of uz3480.craftum[.]io
uz3480.craftum[.]io appears to be a subdomain hosted on the Craftum website-building platform rather than a standalone branded domain. Based on the page title and screenshot, the site presents a generic sign-in form requesting an email address and password, with very little contextual information about the service, organization, or purpose of the login page.
The domain itself does not indicate a recognizable business, product, or institution, and the page does not appear to provide normal supporting content such as company details, navigation, legal pages, or service descriptions. This kind of minimal credential-entry page on a hosted subdomain may be used for legitimate temporary projects, but it is also commonly associated with deceptive login harvesting pages.
Safety Assessment for uz3480.craftum[.]io
Multiple security signals indicate elevated risk at the time of this scan. The URL was flagged by 11 out of 92 security engines, with several classifying it as phishing, malicious, suspicious, or fraud-related. In addition, multiple web-classification providers categorized the site as phishing, fraud, or spam-related, which materially increases concern beyond a single low-confidence heuristic.
The screenshot and metadata also align with that assessment: the page is a bare sign-in form on an unbranded hosted subdomain, asking for email credentials without clearly identifying the service or operator. That presentation may be consistent with credential collection rather than a transparent login experience. A malware scan also identified a flagged external resource loaded from another domain, which may indicate suspicious third-party content or infrastructure.
Some reputation sources were clean at the time of this scan, including major blacklist checks and DNS-based blocklists, so the evidence is not universally negative. However, based on the combination of multi-engine detections, phishing-related categorization, and the highly generic login-page design, this website may pose potential risks to visitors.
Technical Description
The site was served over HTTPS with a valid TLS certificate issued by GlobalSign nv-sa, expiring in December 2026. It appears to run behind an nginx web server on infrastructure hosted by JSC "TIMEWEB" in St Petersburg, Russia, using the IP address 92.255.111.71. The domain is a subdomain under craftum.io, and the parent hosting setup suggests it may be using a site-builder or hosted landing-page environment.
WHOIS data indicates the domain has existed for several years, which can sometimes reduce concern compared with newly registered domains, but that factor is outweighed here by the phishing-related detections. DNSSEC appears to be unsigned, which is common but means DNS responses do not benefit from DNSSEC validation. An external resource from a separate domain was flagged during scanning, which may represent an additional technical risk indicator at the time of analysis.
Share your experience with this website. Was it safe? Did you encounter any issues?