ww1-dkb.webworkonline.co
Category: Phishing
To use full-featured product, you have to purchase a license for Combo Cleaner. Limited seven days free trial available. Combo Cleaner is owned and operated by RCS LT, the parent company of PCRisk.com.
Description of ww1-dkb.webworkonline.co
The domain ww1-dkb.webworkonline.co currently appears to display a default hosting page generated by Plesk rather than a finished public website. The screenshot shows standard Plesk branding, a login prompt for the hosting control panel, and links to Plesk documentation, support resources, and related services. Based on the visible content, the page seems to be part of a newly configured or undeveloped hosting environment.
The domain structure is notable because it uses a subdomain format that includes "ww1-dkb," which can resemble naming patterns sometimes seen in look-alike or campaign-specific subdomains. However, the visible page content itself is generic hosting-panel material rather than a branded banking portal or active service. Based on available data, the site appears to be hosted on cloud infrastructure and may currently serve as a placeholder, misconfiguration page, or inactive setup page rather than a fully launched website.
Safety Assessment for ww1-dkb.webworkonline.co
Scan results show several caution signals at the time of this scan. The domain was flagged by 6 out of 91 security engines, and multiple web-classification sources categorized it as phishing or fraud-related. In addition, one phishing-focused threat database listed the domain, and the domain's IP address appears on one mail-reputation blocklist. Those findings are more concerning because the domain is very new, not ranked for traffic, and uses a naming pattern that may resemble a look-alike for a financial brand.
At the same time, the visible page content is only a default Plesk landing page, and the malware scan did not identify confirmed malicious files. The generic suspicious-object findings in links and domain references appear to be low-confidence heuristic matches tied to the placeholder page template rather than proof of malware by themselves. Even so, the combination of multi-engine phishing detections, a phishing-database listing, and the young age of the domain materially raises risk.
Based on these findings, this website may pose potential risks to visitors.
Technical Description
The site uses a valid Let's Encrypt SSL certificate expiring on 2026-09-15 and is served over nginx from an AWS EC2 instance in the eu-central-1 region, with the server geolocating to Frankfurt am Main, Germany. The domain is very new, registered through DYNADOT LLC, and uses Dynadot nameservers. DNSSEC appears to be unsigned at the time of this scan.
From an infrastructure perspective, the page appears to be a standard Plesk default website page rather than a custom application. While valid HTTPS is present, that alone does not establish legitimacy. The combination of a newly registered domain, unsigned DNSSEC, cloud-hosted default content, and external phishing-related detections may indicate an unconfigured host, a disposable setup, or a domain that has been reported before meaningful content was deployed.
Share your experience with this website. Was it safe? Did you encounter any issues?