profileupdate-collaboration[.]stefan-dufva[.]workers[.]dev
Evidence Summary
Analysis of the domain profileupdate-collaboration.stefan-dufva.workers.dev indicates an active credential‑phishing operation. The domain is hosted on Cloudflare’s infrastructure, as evidenced by the registrar entry "Cloudflare, Inc." and the resolution to IP address 188.114.97.3, which belongs to Cloudflare’s network. The domain has been flagged by multiple security vendors; VirusTotal reports six detections out of ninety‑one scanners, and the domain appears on one external blocklist. PhishDestroy has already blocked the domain, demonstrating that at least one anti‑phishing service has identified malicious activity.
No DNS NS records were retrieved, and the page title or SSL certificate details are not currently available, leaving the exact content and certificate posture unverified. Defenders should treat the domain as high‑risk and add it to outbound and inbound URL filtering rules. Network‑level controls can block traffic to the associated IP address (188.114.97.3) and to the entire Cloudflare edge range if broader mitigation is required.
Continuous monitoring of Cloudflare‑hosted subdomains for similar patterns is advised, as the attacker may reuse the same hosting provider for future campaigns. Organizations should also enforce multi‑factor authentication and credential‑reuse detection to mitigate potential credential harvests originating from this domain. Until further forensic analysis of the landing page is possible, the domain should remain blocked and logged for incident response correlation.
Data Coverage
Threat Response Pipeline
Blocklist coverage
10 monitored external feeds · stored snapshot Aug 11, 2026
10 monitored external feeds No match
Detection timeline
-
First recorded
First stored value: Reachable
Technologies
3 high-confidence technologies identified
VirusTotal Analysis
Archived Evidence
Site Performance Analysis
Google PageSpeed Insights — mobile performance audit of profileupdate-collaboration.stefan-dufva.workers.dev · checked Aug 1, 2026
Were You Affected by This Site?
If credentials, payment data, or files were exposed, report the incident immediately. Change affected passwords, revoke active sessions, and scan the device.
Report to Your Local Authorities
Select your country to get official cybercrime contacts, or create a complaint draft →.
Check Any Domain
Threat analysis using stored blocklist, WHOIS, DNS, and public scan evidence
Scan NowReport Phishing
Submit suspicious domains to our threat database — protect the community
ReportLive Threat Feed
Recent phishing reports and observed availability changes
MonitorStay Informed, Stay Safe
Monitor live threats or contest this listing if you believe it's a false positive