x-novobanco.com
Category: Spyware And Malware
To use full-featured product, you have to purchase a license for Combo Cleaner. Limited seven days free trial available. Combo Cleaner is owned and operated by RCS LT, the parent company of PCRisk.com.
Description of x-novobanco.com
x-novobanco.com appears to present itself as an online banking login page associated with novobanco, using branding, page title text, and interface elements that resemble a financial-services portal. The screenshot shows fields for a membership number and PIN, along with a virtual keypad and Portuguese-language security messaging, which suggests the page is designed to collect banking credentials.
Based on the domain structure and visible content, this does not appear to be a normal corporate banking domain. The added prefix in the hostname, the extremely recent registration date, and the lack of broader site content may indicate that the page was set up to imitate a legitimate banking login experience rather than to operate as an official bank website.
The available classifications also place the domain in phishing, fraud, and malware-related categories. Taken together, the site appears to be a credential-harvesting page targeting users who may believe they are interacting with a real online banking service.
Safety Assessment for x-novobanco.com
Multiple security signals indicate elevated risk at the time of this scan. The domain was flagged by 15 out of 91 security engines, with detections centered on phishing and malicious activity, and it was also categorized by web-classification providers as phishing, fraud, spyware, or malware-related. In addition, one threat database listing was present, and the domain's IP address was listed on one mail-reputation blocklist, which is a weaker signal on its own but still worth noting.
The page content itself raises further concern. The domain closely resembles the name of a known banking brand while adding an extra prefix, and the screenshot shows a banking-style login form requesting account access details and PIN entry. Combined with the domain age of 0 days and the absence of any established traffic ranking, this pattern is commonly associated with short-lived impersonation pages intended to capture sensitive information.
Although one malware scan reported no directly flagged files and only generic suspicious-object references, that cleaner result is outweighed here by the broader multi-engine phishing consensus, the visible credential-collection interface, and the brand-like domain naming pattern. Based on these findings, this website may pose potential risks to visitors.
Technical Description
The site was using a valid Let's Encrypt SSL certificate at the time of the scan and was served over nginx from IP address 64.89.160.3, hosted by Ghosty Networks LLC in Luxembourg. A valid certificate only indicates that traffic may be encrypted in transit; it does not by itself confirm legitimacy. The domain was registered on the same day as the scan, uses nameservers ns1.erans.ru and ns2.erans.ru, and had no DNSSEC signing enabled.
From a technical-risk perspective, the combination of a newly created domain, unsigned DNSSEC status, limited infrastructure history, and a login page that appears to imitate a banking portal may be concerning. The referenced assets and scripts were generically flagged by one malware scanner, though those detections appear heuristic rather than file-specific malware confirmations.
Share your experience with this website. Was it safe? Did you encounter any issues?