exdoessofc3434[.]dorathea4[.]workers[.]dev
“Google”
Zusammenfassung der Beweislage
This domain, exdoessofc3434.dorathea4.workers.dev, was identified as a brand impersonation phishing site targeting Gmail users, as indicated by its page title 'Google' and confirmed scam classification. Registered on February 21, 2026, through Cloudflare, Inc., the domain resolved to the IP address 142.250.195.132, hosted on Cloudflare’s infrastructure (AS13335). The SSL certificate was issued by Google Trust Services (WE1), a detail that may contribute to the site’s deceptive appearance of legitimacy. Analysis of the domain’s infrastructure reveals the use of Cloudflare nameservers (clyde.ns.cloudflare.com and sofia.ns.cloudflare.com) and technologies such as HSTS and HTTP/3, which are commonly employed to enhance security but can also be leveraged by threat actors to evade detection.
As of July 23, 2026, the domain has been taken offline, returning an HTTP 403 status, which suggests either intervention by the hosting provider or voluntary takedown. The domain appears on at least one security blocklist, and 12 of 93 security vendors on VirusTotal flagged it as malicious, reinforcing its classification as a phishing threat. Gridinsoft assigned a trust score of 0/100, further indicating high risk. While the exact content of the phishing page remains unanalyzed, the combination of its page title, SSL certificate issuer, and hosting on a known content delivery network aligns with tactics used in brand impersonation campaigns.
Defenders should treat this domain as a confirmed phishing threat targeting Gmail users. Organizations are advised to block the domain at the DNS and proxy levels, monitor for related indicators of compromise (IOCs) such as the IP address and SSL certificate thumbprint, and alert users to potential phishing attempts. Given the domain’s use of Cloudflare Workers, additional scrutiny should be applied to similar subdomains under dorathea4.workers.dev or other Cloudflare-hosted phishing infrastructure.
Data Coverage
Erkenntnisse zur Netzwerksicherheit
Pipeline zur Reaktion auf Sicherheitsbedrohungen
Blocklistenabdeckung
10 überwachte externe Feeds · gespeicherter Stand 13.08.2026
Erkennungszeitleiste
-
Domainstatus
Erreichbar → Nicht erreichbar
-
Cloudflare Radar
Cloudflare-Radar-Scan gespeichert · Scan öffnen
-
Cloudflare Radar
Cloudflare-Radar-Scan gespeichert · Scan öffnen
Forensische Erkenntnisse
VirusTotal-Analyse
Website-Performanceanalyse
Google PageSpeed Insights — mobile performance audit of exdoessofc3434.dorathea4.workers.dev · checked Mar 2, 2026
Wurden Sie von dieser Website betroffen?
Wenn Sie Kontoanmeldeinformationen, persönliche oder Zahlungsinformationen eingegeben oder eine Datei von dieser Domain heruntergeladen haben, ergreifen Sie sofort Maßnahmen. Nachfolgend finden Sie Ressourcen, die Ihnen helfen, den Vorfall zu melden und sich zu schützen.
Melden Sie sich bei Ihren örtlichen Behörden
Wählen Sie Ihr Land aus, um Offizielle Kontakte im Bereich Cyberkriminalität oder einen Beschwerdeentwurf erstellen → zu erhalten.
Jede beliebige Domain prüfen
Bedrohungsanalyse anhand gespeicherter Blocklisten, WHOIS, DNS und öffentlicher Scan-Beweise
Jetzt scannenPhishing melden
Melden Sie verdächtige Domains an unsere Bedrohungsdatenbank – schützen Sie die Community
MeldenEchtzeit-Bedrohungsfeed
Aktuelle Phishing-Meldungen und beobachtete Verfügbarkeitsänderungen
ÜberwachenBleiben Sie auf dem Laufenden, bleiben Sie sicher
Beobachten Sie aktuelle Bedrohungen oder legen Sie Widerspruch gegen diesen Eintrag ein, wenn Sie der Meinung sind, dass es sich um einen Fehlalarm handelt