3d446d67[.]mewjdjckc-0sbbc83hhzxsh[.]pages[.]dev
“Worker threw exception | 3d446d67.mewjdjckc-0sbbc83hhzxsh.pages.dev | Cloudflare”
3d446d67.mewjdjckc-0sbbc83hhzxsh.pages.dev — असत्यापित. ब्रांड प्रतिरूपण: Cloudflare; घोटाले का प्रकार: Brand Impersonation. साक्ष्य सारांश: VirusTotal 2/91 (alphaMountain.ai, Forcepoint ThreatSeeker); PhishDestroy score 76/100. रजिस्ट्रार: Cloudflare.
मूल फॉरेंसिक रिकॉर्ड सुरक्षित रखने के लिए नीचे का विस्तृत PhishDestroy AI विश्लेषण अंग्रेज़ी में रखा गया है।
This domain, 3d446d67.mewjdjckc-0sbbc83hhzxsh.pages.dev, is flagged as an active brand impersonation threat targeting Cloudflare. Registered on February 21, 2026, through Cloudflare, Inc., it resolves to the IP 104.21.80.1 (AS13335, Cloudflare, Inc.) and is hosted within Cloudflare's infrastructure. The page title, 'Worker threw exception | 3d446d67.mewjdjckc-0sbbc83hhzxsh.pages.dev | Cloudflare,' explicitly references Cloudflare, reinforcing the impersonation classification. Analysis indicates the domain is currently returning an HTTP 500 status, which may suggest either a misconfigured phishing kit or an attempt to evade detection by presenting as a broken service. Technical indicators include the use of Cloudflare's Pages platform, HSTS, and HTTP/3, aligning with legitimate Cloudflare-hosted services but also providing cover for malicious activity. The SSL certificate is issued by Google Trust Services (WE1), a common certificate authority, which does not inherently indicate malicious intent. Two of 93 security vendors on VirusTotal have flagged this domain, and it appears on at least one security blocklist, including PhishDestroy. The domain's Gridinsoft trust score is 0/100, further supporting its classification as high-risk. Defenders should treat this domain as part of a Cloudflare impersonation campaign. The use of Cloudflare's own infrastructure complicates detection, as traffic and hosting patterns may blend with legitimate services. Network-level blocking of the domain and its resolving IP (104.21.80.1) is recommended, alongside monitoring for similar patterns in subdomains under *.pages.dev. Additional analysis of the domain's historical content or redirects, if available, may provide further context on the specific phishing tactics employed. The domain remains active as of July 12, 2026, and should be considered a live threat.
धमकी प्रतिक्रिया पाइपलाइन
सार्वजनिक ब्लॉकलिस्ट स्थिति
तकनीकें · 3 identified
HTTP Strict Transport Security — forces browsers to use HTTPS connections only.
Web infrastructure and security company providing CDN, DDoS mitigation, and DNS services.
www.cloudflare.comThird major version of HTTP protocol, built on QUIC for faster, more reliable connections.
वायरसटोटल विश्लेषण
साक्ष्य और बाहरी रिपोर्टें
क्या आप इस साइट से प्रभावित हुए?
यदि आपने खाता क्रेडेंशियल, व्यक्तिगत या भुगतान जानकारी दर्ज की है, या इस डोमेन से कोई फ़ाइल डाउनलोड की है, तो तुरंत कार्रवाई करें। घटना की रिपोर्ट करने और अपनी सुरक्षा करने में आपकी सहायता के लिए नीचे संसाधन दिए गए हैं।
अपने स्थानीय अधिकारियों को रिपोर्ट करें
आधिकारिक साइबर अपराध संपर्क, या एक शिकायत ड्राफ्ट बनाएं → प्राप्त करने के लिए अपना देश चुनें।
किसी भी डोमेन की जाँच करें
संग्रहीत ब्लॉकलिस्ट, WHOIS, DNS और सार्वजनिक स्कैन साक्ष्य का उपयोग करके खतरे का विश्लेषण
अभी स्कैन करेंफ़िशिंग की रिपोर्ट करें
संदिग्ध डोमेन हमारे थ्रेट डेटाबेस में जमा करें — समुदाय की सुरक्षा करें
रिपोर्ट करेंसीधा खतरा फीड
हाल की फ़िशिंग रिपोर्टें और उपलब्धता में परिवर्तन देखे गए
निगरानी करेंजानकारी में रहें, सुरक्षित रहें
लाइव खतरों की निगरानी करें या यदि आपको लगता है कि यह एक गलत सकारात्मक है तो इस लिस्टिंग को चुनौती दें।