Analysis of tzr-iejfd.destiny72.workers.dev on 2026-07-29 indicates the domain is actively used in a generic phishing campaign. The domain resolves to the IPv4 address 172.67.130.173, which is part of Cloudflare’s network, and its registration is listed under Cloudflare, Inc. No authoritative nameserver information could be retrieved (NS_NOT_FOUND). The domain appears on a single security blocklist and is flagged by PhishDestroy.
VirusTotal records show that the domain was submitted to 91 scanning engines; none of the engines reported a detection at the time of analysis. While the lack of detections does not constitute proof of safety, the blocklist inclusion and PhishDestroy flag together suggest malicious intent. No page title, SSL certificate details, HTTP status code, Safe Browsing verdict, or OTX references are currently available, limiting content‑level assessment.
Defenders should block the domain at DNS and network perimeter, monitor outbound traffic to the associated IP address, and add the domain to internal threat intelligence feeds. Ongoing observation of Cloudflare‑hosted infrastructure with similar characteristics is advised, as the service can be rapidly repurposed for malicious campaigns. The domain remains active, and its risk status should be treated as under investigation pending further evidence.