linktron72[.]worker-ca6d8421[.]workers[.]dev
“Coming Soon”
Pengamatan tersimpan
Perbedaan judul yang diamati
Ringkasan bukti
This domain, linktron72.worker-ca6d8421.workers.dev, is flagged as an active credential harvesting endpoint targeting cryptocurrency users. Analysis indicates the infrastructure is designed to mimic legitimate wallet or decentralized application interfaces, likely employing social engineering tactics to extract private keys, seed phrases, or authentication credentials. No explicit brand impersonation is evident from available metadata, though the use of a generic 'Coming Soon' page title suggests pre-deployment staging or dynamic content loading via client-side scripts. The domain does not currently exhibit overt drainer kit signatures, but its association with known blocklists and cryptocurrency-focused detection engines implies a specialized threat vector. Infrastructure analysis reveals the domain was provisioned through Cloudflare, Inc. on February 8, 2019, and resolves to the IP address 188.114.96.3, a Cloudflare-operated node. The endpoint is secured with an SSL certificate issued by Google Trust Services and enforces HTTP Strict Transport Security (HSTS) over HTTP/3, indicating a deliberate effort to appear legitimate while maintaining operational resilience. Detection metrics show the domain is flagged by 2 of 95 security vendors on VirusTotal, with additional blocking by three specialized security systems: MetaMask, SEAL, and PhishDestroy. Despite its creation date predating the observed malicious activity, the domain's subdomain structure and Cloudflare Workers integration suggest recent weaponization. Current status remains active, with no evidence of takedown or mitigation at the registrar level. The elevated risk level stems from the domain's cryptocurrency-specific targeting and its presence on multiple high-confidence blocklists. Response actions should include immediate blocking of the domain and IP at network perimeters, alongside monitoring for related subdomains or certificate reuse. Users are advised to verify all decentralized application interactions via official sources and disable JavaScript execution for untrusted origins to mitigate client-side credential extraction. The domain's use of Cloudflare infrastructure complicates traditional takedown efforts, necessitating continued vigilance for evolving attack patterns.
Data Coverage
Intelijen Keamanan Jaringan
Alur Tanggapan Ancaman Pipeline
Cakupan daftar blokir
10 sumber eksternal dipantau · snapshot tersimpan 11/08/2026
Linimasa deteksi
-
Status domain
Dapat dijangkau → Tidak dapat dijangkau
-
Status domain
Dapat dijangkau → Tidak dapat dijangkau
-
Cloudflare Radar
Pemindaian Cloudflare Radar tersimpan · Buka pemindaian
Analisis VirusTotal
Analisis Performa Situs
Google PageSpeed Insights — mobile performance audit of linktron72.worker-ca6d8421.workers.dev · checked Jun 27, 2026
Apakah Anda Terpengaruh oleh Situs Ini?
Jika Anda memasukkan kredensial akun, informasi pribadi atau pembayaran, atau mengunduh file dari domain ini, segera ambil tindakan. Di bawah ini adalah sumber daya untuk membantu Anda melaporkan insiden tersebut dan melindungi diri Anda sendiri.
Laporkan kepada Pihak Berwenang di Daerah Anda
Pilih negara Anda untuk mendapatkan kontak resmi kejahatan dunia maya, atau membuat draf pengaduan →.
Periksa Domain Apa Pun
Analisis ancaman menggunakan daftar blokir yang disimpan, WHOIS, DNS, dan bukti pemindaian publik
Pindai SekarangLaporkan Phishing
Laporkan domain yang mencurigakan ke basis data ancaman kami — lindungi komunitas
LaporanPemberitahuan Ancaman Real-Time
Laporan phishing terbaru dan perubahan ketersediaan yang diamati
PantauTetap Terinformasi, Tetap Aman
Pantau ancaman secara langsung atau ajukan keberatan terhadap daftar ini jika Anda yakin ini merupakan false positive