index-546[.]hank-andrews-verusresearchs-net-s-account[.]workers[.]dev
“Worker threw exception | index-546.hank-andrews-verusresearchs-net-s-account.workers.dev | Cloudfla…”
index-546.hank-andrews-verusresearchs-net-s-account.workers.dev — No verificado. Suplantación de marca: Cloudflare; Tipo de estafa: Brand Impersonation. Resumen de las pruebas: VirusTotal 15/91 (ADMINUSLabs, Criminal IP, BitDefender, Chong Lua Dao, CyRadar); PhishDestroy score 95/100. Registrador: Cloudflare Workers.
El análisis detallado de PhishDestroy AI se mantiene en inglés para conservar el registro forense original.
This domain, index-546.hank-andrews-verusresearchs-net-s-account.workers.dev, is an active credential phishing threat designed to harvest user login credentials through fraudulent authentication interfaces. Analysis indicates the domain specifically targets individuals by impersonating legitimate services, likely leveraging social engineering tactics to deceive victims into submitting sensitive information. The domain is currently operational and has not been taken down despite security detections. Infrastructure analysis reveals the domain is registered through Cloudflare Workers and resolves to the IP address 188.114.96.3, located in Canada under Cloudflare, Inc. It was created on May 02, 2026, though this date may reflect automated registration processes rather than typical domain lifecycle timelines. The domain is flagged by 16 of 95 security vendors on VirusTotal, with a Let's Encrypt SSL certificate (serial number E7) providing HTTPS encryption to lend false legitimacy. It appears on one security blocklist, specifically PhishDestroy, and displays a Cloudflare Worker exception error, suggesting either misconfiguration or evasion attempts. The risk level for this domain is classified as high due to its active status, credential harvesting intent, and use of reputable hosting infrastructure to bypass initial scrutiny. Organizations and individuals are advised to block the domain at the network level and add the IP address 188.114.96.3 to firewall deny lists. Security teams should monitor for any attempts to access this domain from internal networks and conduct user awareness training to recognize phishing indicators, such as unusual subdomain structures and Cloudflare Worker-based URLs. Endpoint protection systems should be updated to include this domain in real-time threat intelligence feeds to prevent potential data breaches.
Proceso de respuesta ante amenazas Pipeline
Estado de la lista de bloqueados pública
Inteligencia de dominios
Detalles técnicosDNS, SAN de SSL, marcas de tiempo
Análisis de VirusTotal
Datos y informes externos
¿Te ha afectado esta página web?
Si ingresó credenciales de cuenta, información personal o de pago, o descargó un archivo de este dominio, tome medidas inmediatas. A continuación encontrará recursos que le ayudarán a informar el incidente y protegerse.
Informa a las autoridades locales
Seleccione su país para obtener contactos oficiales de cibercrimen o crear un borrador de queja →.
Comprobar cualquier dominio
Análisis de amenazas utilizando listas de bloqueo almacenadas, WHOIS, DNS y evidencia de escaneo público
Escanear ahoraDenunciar un intento de phishing
Envía los dominios sospechosos a nuestra base de datos de amenazas: protege a la comunidad
DenunciarFlujo de amenazas en tiempo real
Informes de phishing recientes y cambios de disponibilidad observados
MonitorizarMantente informado, mantente a salvo
Supervisa las amenazas en tiempo real o impugna esta entrada si crees que se trata de un falso positivo.