# sdworxpayverifing.com — MALICIOUS > sdworxpayverifing.com is an active phishing site targeting users. Stay alert and avoid sharing sensitive info. Check phishdestroy.io for updates. ## Summary PhishDestroy identifies sdworxpayverifing.com as a medium-risk generic phishing domain designed to deceive users into revealing confidential information. Such threats can lead to identity theft and financial loss, highlighting the importance of vigilance. This domain was registered recently on October 29, 2025, through Ultahost, Inc. It resolves to IP 172.67.144.97 and is currently active. VirusTotal flags it by 5 out of 95 security vendors, indicating emerging suspicion about its intent. Users should avoid interacting with sdworxpayverifing.com, refrain from entering personal or payment details, and report any suspicious activity. Regularly updating security software and verifying URLs before clicking can help mitigate risks. ## Threat Details - Verdict: MALICIOUS - Site status: alive (HTTP 403) ## Domain Intelligence - Registered: 2025-10-29 14:55:19 - Registrar: Ultahost, Inc. - IP: 172.67.144.97 - Nameservers: kia.ns.cloudflare.com roan.ns.cloudflare.com ## Detection Status - VirusTotal: 5 vendors flagged Vendors: ["ADMINUSLabs", "alphaMountain.ai", "CyRadar", "Fortinet", "SOCRadar"] - Google Safe Browsing: clean - Blocklists: 0 hits ## Evidence - Screenshot: https://i.ibb.co/NgBxthN5/dc2a67831a9c.png - Cloudflare Radar: https://radar.cloudflare.com/scan/bda30ce2-c071-412a-80fa-076e0090730f - PhishDestroy: https://phishdestroy.io/domain/sdworxpayverifing.com/ - LLM endpoint: https://phishdestroy.io/domain/sdworxpayverifing.com/llm.txt ## If You Visited This Site 1. Change any passwords you may have entered 2. Enable 2FA on all related accounts 3. Monitor your accounts for unauthorized activity 4. Report to: FBI IC3, Europol, local authorities --- Report by PhishDestroy | https://phishdestroy.io/domain/sdworxpayverifing.com/ Last updated: 2026-03-19