danf-up01[.]w16-oct[.]workers[.]dev
“Suspected phishing site | Cloudflare”
संग्रहीत अवलोकन
देखा गया शीर्षक अंतर
साक्ष्य सारांश
PhishDestroy identifies an active fake invoice delivery scam hosted on danf-up01.w16-oct.workers.dev, posing as a legitimate document delivery platform. This Workers.dev subdomain is weaponized to distribute malicious payloads or harvest credentials under the guise of delivering time-sensitive invoices. The threat is categorized as generic phishing with an undetermined risk level, pending further behavioral analysis.
This domain exhibits multiple indicators of compromise (IOCs) that warrant heightened scrutiny. VirusTotal scans show 0 detections out of 95 engines, indicating the payload remains undetected by current signatures. The domain resolves to IP 172.67.154.39, a Cloudflare infrastructure address commonly abused for evasive hosting. Registered via Cloudflare, Inc., the domain leverages Google Trust Services’ SSL certificate to mimic legitimate encryption, increasing its deceptive effectiveness. The Workers.dev subdomain framework suggests rapid deployment capabilities, allowing threat actors to spin up new instances with minimal effort. As of the latest analysis, there are no confirmed entries on public blocklists or threat intelligence feeds.
To mitigate exposure to this scam, users must avoid accessing danf-up01.w16-oct.workers.dev or any associated links claiming to deliver invoices. Enterprises should configure email filtering rules to block domains resolving to Cloudflare IPs or Workers.dev subdomains in unsolicited messages. Employees should verify document deliveries through official portals and report suspicious links immediately. Security teams are advised to monitor for SSL certificate issuance by Google Trust Services for Workers.dev subdomains outside approved workflows. Blocking IP 172.67.154.39 at the network perimeter may reduce accidental exposure.
Data Coverage
नेटवर्क सुरक्षा इंटेलिजेंस
धमकी प्रतिक्रिया पाइपलाइन
ब्लॉकलिस्ट कवरेज
10 निगरानी वाले बाहरी स्रोत · संग्रहीत स्नैपशॉट 12/08/2026
फॉरेंसिक इंटेलिजेंस
वायरसटोटल विश्लेषण
साइट प्रदर्शन विश्लेषण
Google PageSpeed Insights — mobile performance audit of danf-up01.w16-oct.workers.dev · checked Apr 15, 2026
क्या आप इस साइट से प्रभावित हुए?
यदि आपने खाता क्रेडेंशियल, व्यक्तिगत या भुगतान जानकारी दर्ज की है, या इस डोमेन से कोई फ़ाइल डाउनलोड की है, तो तुरंत कार्रवाई करें। घटना की रिपोर्ट करने और अपनी सुरक्षा करने में आपकी सहायता के लिए नीचे संसाधन दिए गए हैं।
अपने स्थानीय अधिकारियों को रिपोर्ट करें
आधिकारिक साइबर अपराध संपर्क, या एक शिकायत ड्राफ्ट बनाएं → प्राप्त करने के लिए अपना देश चुनें।
किसी भी डोमेन की जाँच करें
संग्रहीत ब्लॉकलिस्ट, WHOIS, DNS और सार्वजनिक स्कैन साक्ष्य का उपयोग करके खतरे का विश्लेषण
अभी स्कैन करेंफ़िशिंग की रिपोर्ट करें
संदिग्ध डोमेन हमारे थ्रेट डेटाबेस में जमा करें — समुदाय की सुरक्षा करें
रिपोर्ट करेंसीधा खतरा फीड
हाल की फ़िशिंग रिपोर्टें और उपलब्धता में परिवर्तन देखे गए
निगरानी करेंजानकारी में रहें, सुरक्षित रहें
लाइव खतरों की निगरानी करें या यदि आपको लगता है कि यह एक गलत सकारात्मक है तो इस लिस्टिंग को चुनौती दें।