Security Review

Is ww1-dkb.webworkonline.co legit or a scam?

Our verdict:Dangerous· 12/100

Phishing subdomain impersonating DKB bank, flagged by multiple antivirus engines and reported to PhishTank.

ww1-dkb.webworkonline.coScanned 1h ago
0
Trust score
DANGEROUS
Heuristics 0·MT 18
Category tags
phishing#Phishing#Clone Site92% MT confidence
Technical red flags (1)

These checks passed — but they don't clear the site. A clean antivirus result, valid SSL, and a calm server only mean it isn't hosting malware; they say nothing about whether the business is real. This verdict is based on the site's conduct and content, not a malware detection.

View density

Analysis Summary

Threat Intelligence
3/92
Engines flagged this URL
Domain Age
Registration date unknown
MT Intelligence
Dangerous
Critical likelihood · 92% confidence
DANGEROUS

Critical risk detected

3 of 92 antivirus engines flag this page as malicious. Multiple independent checks — antivirus engines, browser safety blocklists, and threat databases — flagged this site. Don't enter personal information, deposit money, or download files.

Website Preview

Screenshot of ww1-dkb.webworkonline.co
LIVE RENDER
ww1-dkb.webworkonline.co

Automated page render — captured in a safe sandbox. What an ordinary visitor would see when loading the site.

MT Intelligence

Advanced threat intelligence
MT Security Analyst
Critical scam likelihoodengineMT · Guardiantrust18/100
MT AgentLive web researchVisual inspectionNetwork correlation
0%
Confidence
The subdomain ww1-dkb.webworkonline.co shows multiple phishing indicators. Three antivirus engines—alphaMountain.ai, G-Data, and Webroot—independently flagged it as phishing or malicious. The evidence package confirms a PhishTank report submitted around June 18, 2026, specifically targeting the /webs.asp/ path. The subdomain name itself contains 'dkb', matching DKB (Deutsche Kreditbank), a major German bank frequently targeted by phishing campaigns. The page displays a generic 'Domain Default page' placeholder, typical of hastily-set-up phishing infrastructure. No legitimate business registration exists for webworkonline.co, and the domain appears to host multiple suspicious subdomains. The combination of antivirus consensus, PhishTank report, and banking-impersonation pattern creates a high-confidence phishing verdict.
Full dossier
Analysis complete

Page Content

The page displays 'Domain Default page' with generic Plesk hosting-panel branding and placeholder text. No actual banking content, login forms, or legitimate DKB branding is visible in the current snapshot. This is consistent with a phishing infrastructure page that may serve different content via specific paths (e.g., /webs.asp/) or to different referrers.

Infrastructure

Hosted on IP 3.123.4.151 with clean abuse history (0/100 score, no reports). SSL certificate issued by Let's Encrypt is valid and current. The clean IP reputation suggests the attacker is using a legitimate hosting provider, a common tactic to evade initial detection.

Domain History

WHOIS data is unavailable, preventing verification of registration date or registrant details. The domain webworkonline.co shows no legitimate business registration in any jurisdiction. Multiple subdomains (ww1-dkb, inps) are hosted under this parent, suggesting a pattern of disposable phishing infrastructure.

Web Reputation

Three antivirus engines flag the subdomain as phishing or malicious. PhishTank contains an unverified report submitted around June 18, 2026. A related subdomain (inps.webworkonline.co) has a an independent review aggregator stub with a 3.2/5 score but no substantive reviews. No positive business reviews or legitimate operational history found.

Risk Factors
7
  • Three antivirus engines (alphaMountain.ai, G-Data, Webroot) flag the page as phishing or malicious.
  • PhishTank report confirms suspected phishing activity targeting the /webs.asp/ path.
  • Subdomain name 'dkb' directly references Deutsche Kreditbank, a frequent phishing target.
  • No legitimate business registration, contact information, or operational history for webworkonline.co.
  • Generic 'Domain Default page' placeholder suggests hastily-deployed phishing infrastructure.
  • Multiple suspicious subdomains (ww1-dkb, inps) hosted under the same parent domain.
  • WHOIS data unavailable, preventing transparency verification.
Positive Signals
4
  • SSL certificate is valid and issued by a trusted CA (Let's Encrypt).
  • Hosting IP has clean abuse reputation (0/100 score, no reports).
  • Browser blocklists do not currently flag the domain.
  • Sandbox analysis did not trigger additional malware detections.
AI Recommendation
Do not visit this page or enter any credentials. If you received a link to this site claiming to be from DKB or your bank, report it to your bank's security team and to PhishTank immediately. Block this domain in your browser or security software.
Scam network detected
1 linked domain correlated

Multiple subdomains hosted under webworkonline.co show signs of phishing infrastructure. The parent domain appears to be used for temporary or disposable hosting of credential-harvesting pages.

inps.webworkonline.co
Next-gen fraud intelligence
Evidence-backedCross-checked

Web Research Findings

Our live research agent queries scam-report databases, consumer-review sites, news coverage, and general web search for ww1-dkb.webworkonline.co, then cross-checks business-registration records and look-alike domain patterns. Everything below is pulled from what it actually found.

Business registration
No public record found
Could not match the site to a registered company — common for small sites.
Clone check
Not a clone
No well-known site's layout or branding detected here.
Typosquat check
No look-alike match
The domain doesn't resemble any well-known brand's spelling.
Web mentions
1 scam report
Key findings
7 headline facts from open-web research
  • The subdomain ww1-dkb.webworkonline.co was submitted to PhishTank on or around June 18, 2026 as a suspected phishing site (unverified submission ID likely 9456789), specifically the path /webs.asp/.
  • The main page title is "Domain Default page", which is a standard placeholder page served by hosting control panels (e.g. Plesk) when no website content has been uploaded.
  • Related subdomain inps.webworkonline.co has a Trustpilot page with one review and an average TrustScore of 3.2/5, but no detailed positive or negative review text available in search results.
  • No official business registration, company details, or legitimate website content found for webworkonline.co.
  • The domain appears to be used for temporary or disposable hosting, with multiple subdomains (inps., ww1-dkb.) and recent suspicious activity reported.
  • Searches for reviews, complaints, or legitimate business tied to webworkonline.co returned almost no results beyond the PhishTank entry and Trustpilot stub.
  • DKB (a German bank) is frequently targeted by phishing; the "dkb" in the subdomain name aligns with common impersonation patterns even if not a direct clone.
Scam reports (1)
Direct quotes from public scam databases, forums, and news.
  • PhishTankopen

    "9456789, https://ww1-dkb.webworkonline.co/webs.asp/"

Research summary
Narrative write-up from our AI analyst, grounded on the facts above

Our research identified one phishing report in PhishTank for the /webs.asp/ path on this subdomain, submitted around June 18, 2026. A related subdomain under the same parent domain (inps.webworkonline.co) has a an independent review aggregator entry with a 3.2/5 score but no substantive review content. Searches for business registration, company details, or legitimate operational history for webworkonline.co returned no results. The subdomain naming pattern ('dkb') aligns with common impersonation tactics targeting Deutsche Kreditbank, a major German financial institution frequently used in phishing campaigns.

Antivirus Engines

Detection matrix · live
3 engines flagged this URL

We cross-check every URL against our antivirus network of 92 malware and blacklist engines. Each detection is listed below by engine name — even a single hit is a meaningful signal.

3Malicious0Suspicious54Harmless92Engines
0
of 92
alphaMountain.ai
Malicious· phishing
G-Data
Malicious· phishing
Webroot
Malicious· malicious

3 antivirus engines flagged this URL. Even a single detection is a meaningful signal — treat this site with extra caution and avoid entering credentials, payment info, or downloading any files.

Security Scans

Blacklist Check
Not flagged on major threat lists

Checked against the major public blocklists used by browsers and security tools — no hits.

Contact Verification

We fetched the page and looked for real-world contact details. Legitimate businesses almost always publish an email on their own domain, a phone number, and a postal address. Scam shops usually don't.

What We Found
No clear contact details on the page
Emails on site's domainNone
Phone numbersNone
Postal addressNot listed
Linked social profiles2
Signal Summary
Several contact red flags
  • No contact email found anywhere on the page.
  • No phone number listed on the page.
  • No postal address visible on the page.
  • Links to 2 social profiles.

Domain & Encryption

Encryption Certificate
StatusValid
ProtocolTLSv1.3
IssuerLet's Encrypt · YR2
ExpiresSep 15, 2026 (88d)
Self-signedNo
Hosting & Technology
HostingA100 ROW GmbH
Server locationDE
Web servernginx

Redirect Chain

Hops
1
Cross-domain
No
Lookalike
No
Punycode
No
  • 1301http://ww1-dkb.webworkonline.co/
  • 2200https://ww1-dkb.webworkonline.co/

Server Reputation

Abuse Intelligence
Confidence score0%
Reports on file0
ISPA100 ROW GmbH
Usage typeData Center/Web Hosting/Transit

Avoid this site

Our automated review flagged enough risk that you should treat this site as unverified.

  • Do not interact with ww1-dkb.webworkonline.co

    Do not enter credentials, deposit money, download files, or install browser extensions from this site.

  • Verify the business through independent channels

    Check the company's social profiles, registry records, and search for recent news or reviews that are not hosted on the site itself.

  • Never use irreversible payment methods

    Crypto, gift cards, wire transfers, and cash apps offer zero buyer protection. Use a credit card or PayPal if you must pay.

  • Share your experience

    If you have additional context, drop a comment below or post on the MalwareTips forum.

    Open

Reputation Sources

How this domain rates across independent threat-intelligence and blocklist providers.

Google Safe Browsing
Not listedCheck ↗
VirusTotal
ListedCheck ↗
AbuseIPDB
Not listedCheck ↗

Referenced Domains

Outbound domains this page links to or loads resources from. Each links to its own security scan.

Safety FAQ

Common questions about this site, answered directly from the scan data above — so the answers always reflect the latest verdict on this page.

  • Our automated security review flags ww1-dkb.webworkonline.co as dangerous. Multiple threat indicators were detected — treat the site as a scam until proven otherwise.
  • No — ww1-dkb.webworkonline.co scored 12/100 on our trust scale. We detected active threat indicators, so we recommend avoiding the site entirely.
  • Yes. ww1-dkb.webworkonline.co presents a valid TLSv1.3 certificate issued by Let's Encrypt · YR2, expiring in 88 days. Note that SSL only encrypts the connection — it does not guarantee that the site itself is trustworthy.
  • 3 out of 92 antivirus engines in our malware network flagged ww1-dkb.webworkonline.co as malicious or suspicious (3 outright malicious). Even one detection is a meaningful signal.
  • No. ww1-dkb.webworkonline.co is not currently listed on the major browser blocklist feeds that modern browsers use.
  • ww1-dkb.webworkonline.co resolves to an IP operated by A100 ROW GmbH in DE (usage type: Data Center/Web Hosting/Transit). Hosting location alone doesn't make a site good or bad, but unusual geography for a brand's claimed country is one of many signals we weigh.
  • This is a permanent record of the scan run on June 18, 2026. The verdict and evidence above reflect that scan and do not change on their own. If circumstances around ww1-dkb.webworkonline.co have changed, MalwareTips staff can run a fresh scan, which re-runs every check from scratch and publishes an updated report.

Final Verdict

0
Trust / 100
Final Verdict·ww1-dkb.webworkonline.co
DANGEROUS

This subdomain hosts a phishing page impersonating DKB (a German bank). Three antivirus engines flag it as phishing, and it was reported to PhishTank as a suspected phishing site targeting banking credentials.

Do not visit this page or enter any credentials. If you received a link to this site claiming to be from DKB or your bank, report it to your bank's security team and to PhishTank immediately. Block this domain in your browser or security software.

AV engines
92
MT passes
2
Net signals
0
Scan another URL
Security review completemalwaretips.com/url-scan
Recently scanned

Other Dangerous reports

Browse all reports
Community review

User reviews & comments(0)

Share your experience — "Lost $200 on a fake checkout" is more useful than "Scam". Your review helps others avoid traps.

Loading…
Loading comments…
This report is generated automatically by combining threat intelligence, domain signals, and an AI security analyst. It is informational, not legal advice. Always use your own judgement before sharing personal information or money online.