trzr3545rhkdtz[.]sd8g[.]workers[.]dev
“Welcome to Suite”
Evidence Summary
Analysis indicates that the subdomain trzr3545rhkdtz.sd8g.workers.dev is currently classified as a generic phishing resource. The domain is hosted on the Cloudflare Workers platform, as indicated by the “workers.dev” suffix, which provides serverless edge execution and often serves as a convenient front‑end for malicious actors. VirusTotal records show that the domain was submitted to 91 scanning engines, none of which raised a detection at the time of analysis. While the lack of detections does not imply benign intent, it demonstrates that the payload or landing page has not yet been fingerprinted by public scanners.
The domain is listed on a single external blocklist and has been explicitly added to the PhishDestroy blocklist, confirming that at least one anti‑phishing community has observed malicious activity associated with it. No additional intelligence such as registrar details, IP address, SSL certificate metadata, HTTP response codes, Safe Browsing verdicts, or Open Threat Exchange tags are presently available. Consequently, the precise hosting infrastructure, certificate validity, and page content remain unknown. The threat is marked as “active” and “under investigation,” indicating ongoing monitoring by security teams.
Defenders should consider adding the domain to network‑level deny lists, enforcing URL filtering policies, and monitoring outbound connections for attempts to resolve or contact the subdomain. Continuous re‑scanning with multi‑engine services is advised to capture any future payload changes. Organizations should also review any user‑reported phishing attempts that reference this domain and correlate them with internal logs to identify potential compromise vectors.
Data Coverage
Threat Response Pipeline
Blocklist coverage
10 monitored external feeds · stored snapshot Aug 13, 2026
10 monitored external feeds No match
Community reports
Reported by 0 community members, first seen Aug 4, 2026
- Unique reported URLs
- 1
Community intelligence
1 community report
CategoryPHISHING
The PhishFort Detection System has flagged this as a domain threat, classified as null. Threat detected at 2026-01-17T23:00:02.530Z.
Technologies
8 high-confidence technologies identified
VirusTotal Analysis
Archived Evidence
Site Performance Analysis
Google PageSpeed Insights — mobile performance audit of trzr3545rhkdtz.sd8g.workers.dev · checked Aug 4, 2026
Lookalike domains
74 stored lookalike domains
Show all (62)
Were You Affected by This Site?
If credentials, payment data, or files were exposed, report the incident immediately. Change affected passwords, revoke active sessions, and scan the device.
Report to Your Local Authorities
Select your country to get official cybercrime contacts, or create a complaint draft →.
Check Any Domain
Threat analysis using stored blocklist, WHOIS, DNS, and public scan evidence
Scan NowReport Phishing
Submit suspicious domains to our threat database — protect the community
ReportLive Threat Feed
Recent phishing reports and observed availability changes
MonitorStay Informed, Stay Safe
Monitor live threats or contest this listing if you believe it's a false positive