small-sunset-9dfe[.]gwendienicolls98[.]workers[.]dev
small-sunset-9dfe.gwendienicolls98.workers.dev — لم يتم التحقق منها. ملخص الأدلة: VirusTotal 0/91; PhishDestroy score 68/100. مسجّل النطاق: Cloudflare Workers.
يبقى تحليل PhishDestroy AI المفصل أدناه باللغة الإنجليزية للحفاظ على السجل الجنائي الرقمي الأصلي.
This domain is flagged as a credential harvesting phishing endpoint targeting users through deceptive login interfaces. Analysis indicates the site mimics legitimate authentication portals to capture usernames, passwords, and session tokens, likely for account takeover or unauthorized access to corporate or personal services. The infrastructure is designed to evade initial detection, as evidenced by its minimal footprint in security telemetry. Infrastructure analysis reveals the domain was registered on April 29, 2026, via Cloudflare Workers, a platform commonly abused for rapid deployment of malicious endpoints. It resolves to IP address 172.67.140.178, hosted within a content delivery network in Canada. The SSL certificate, issued by Let's Encrypt (serial E7), provides encrypted communication to lend credibility to the phishing attempt. Despite its active status, the domain appears on only one security blocklist, and VirusTotal reports 0/95 detections, indicating low initial visibility among security vendors. Users who have visited small-sunset-9dfe.gwendienicolls98.workers.dev should immediately terminate any active sessions and reset credentials for any accounts entered on the site. Network administrators are advised to block the domain and its resolving IP (172.67.140.178) at the perimeter. Endpoints that accessed the domain should be scanned for malware or unauthorized modifications, and logs should be reviewed for signs of credential exfiltration or lateral movement. If multi-factor authentication was not enabled on compromised accounts, it should be enforced immediately to mitigate further risk.
مسار الاستجابة للتهديدات Pipeline
حالة قوائم الحظر العامة
معلومات النطاق
التفاصيل الفنيةDNS، أسماء المجال البديلة (SAN) في بروتوكول SSL، الطوابع الزمنية
تحليل VirusTotal
الأدلة والتقارير الخارجية
هل تأثرت بهذا الموقع؟
إذا أدخلت بيانات اعتماد الحساب أو المعلومات الشخصية أو معلومات الدفع أو قمت بتنزيل ملف من هذا النطاق، فاتخذ إجراءً فوريًا. فيما يلي موارد لمساعدتك في الإبلاغ عن الحادث وحماية نفسك.
أبلغ السلطات المحلية
حدد بلدك للحصول على الاتصالات الرسمية المتعلقة بالجرائم الإلكترونية أو إنشاء مسودة شكوى →.
تحقق من أي نطاق
تحليل التهديدات باستخدام قائمة الحظر المخزنة، وWHOIS، وDNS، وأدلة الفحص العامة
امسح الآنالإبلاغ عن محاولة تصيد احتيالي
أرسل النطاقات المشبوهة إلى قاعدة بيانات التهديدات الخاصة بنا — ساهم في حماية المجتمع
إبلاغتحديثات فورية حول التهديدات
تقارير التصيد الاحتيالي الأخيرة وتغييرات التوفر الملحوظة
مراقبةابقَ على اطلاع، وابقَ آمنًا
راقب التهديدات في الوقت الفعلي أو اعترض على هذا الإدراج إذا كنت تعتقد أنه إنذار كاذب