yg5755.craftum.io
Category: Phishing
To use full-featured product, you have to purchase a license for Combo Cleaner. Limited seven days free trial available. Combo Cleaner is owned and operated by RCS LT, the parent company of PCRisk.com.
Quttera Web Malware Removal is a paid subscription service. Pricing, plans, and trial availability are set by Quttera. Quttera is operated by Quttera Ltd, an independent third-party company unrelated to RCS LT. PCrisk.com may earn a referral commission when users sign up through this link.
Description of yg5755.craftum.io
yg5755.craftum.io appears to be a subdomain hosted on Craftum, a website-building platform, rather than a standalone primary domain. The visible page content shows a generic "Example Domain" style background with an overlaid sign-in form requesting an email address and password, which suggests the page may be intended to collect login credentials rather than present a normal business or informational website.
Based on the domain structure and the screenshot, this page does not appear to represent an established brand, publisher, or organization with clear ownership details. The random-looking subdomain label, lack of page title or descriptive metadata, and minimal content make it difficult to identify a legitimate operator or purpose from the available data.
The overall presentation is more consistent with a temporary landing page or credential prompt than with a fully developed website. In practical terms, it appears to function as a login-themed page hosted under a third-party site builder environment.
Safety Assessment for yg5755.craftum.io
Several scan signals indicate elevated risk at the time of this scan. The domain was flagged by 5 out of 89 security engines, including phishing-related classifications from multiple engines. In addition, the page screenshot shows a generic sign-in form asking for an email address and password while lacking normal identifying details such as branding, navigation, or a clear service description. That combination may be consistent with credential-harvesting activity.
The malware scan also reported suspicious findings in 2 of 3 scanned items and identified flagged external resources loaded from two separate storage or CDN-style domains. While heuristic detections alone can sometimes be low confidence, these findings are more concerning here because they appear alongside multi-engine phishing detections and a login-focused page design. Blacklist and threat-database checks were otherwise limited, with no threats detected by the checked content-malice databases at the time of this scan.
The domain itself is not newly registered, which slightly reduces uncertainty, but its lack of traffic ranking, sparse metadata, and the phishing-oriented page behavior remain notable concerns. Based on these findings, this website may pose potential risks to visitors.
Technical Description
The site uses a valid SSL/TLS certificate issued by GlobalSign and served over an nginx web server. It resolves to IP address 92.255.111.71 and appears to be hosted by JSC "TIMEWEB" in St Petersburg, Russia. The domain is a subdomain of craftum.io, with nameservers ns1.craftum.io and ns2.craftum.io.
DNSSEC appears to be unsigned, which is common but means DNS responses do not benefit from DNSSEC validation. No DNS-based blocklist hits were reported in the provided data. The main technical concerns are not certificate-related, but rather the suspicious page behavior, the use of externally loaded flagged resources, and the mismatch between the generic page presentation and the credential request.
Share your experience with this website. Was it safe? Did you encounter any issues?