note-access-nj2w[.]rob-c2d[.]workers[.]dev
Resumo das evidências
PhishDestroy identifies an elevated-risk crypto credential theft domain hosted at note-access-nj2w.rob-c2d.workers.dev. This Workers.dev subdomain delivers a generic phishing page designed to harvest cryptocurrency wallet credentials or seed phrases under the guise of legitimate access requests. No specific brand impersonation or drainer kit signature is recorded in current feeds, suggesting a broad, opportunistic campaign targeting crypto users. The threat actor leverages Cloudflare Workers for serverless execution, enabling rapid deployment and evasion of traditional hosting-based detection mechanisms.
This domain resolves to IP 188.114.97.3 and is registered via Cloudflare, Inc. Its SSL certificate is issued by Let's Encrypt, facilitating encrypted connections to evade inspection. VirusTotal analysis shows a detection ratio of 16 out of 95 security vendors as of seed 056c79. The domain is not currently flagged in Google Safe Browsing (GSB), but its low VT coverage and Workers.dev origin suggest recent activation and potential for rapid spread. It has likely evaded broad blocklists due to its ephemeral infrastructure and legitimate-looking certificate.
Current status: active and serving phishing content. Immediate action is required to block the domain at DNS and network levels. Users should not access this URL or interact with any content delivered from it. Cryptocurrency users are advised to verify all access links via official channels and to rotate credentials if any interaction has occurred. Remaining risk: elevated due to low detection coverage and potential for rapid propagation across crypto communities. Continuous monitoring and proactive blocking are essential to mitigate exposure until the domain is neutralized by hosting providers or law enforcement takedowns.
Data Coverage
Inteligência de segurança de rede
Pipeline de resposta a ameaças
Cobertura de listas de bloqueio
10 fontes externas monitoradas · instantâneo de 11/08/2026
10 fontes externas monitoradas Sem correspondência
Análise do VirusTotal
Análise de desempenho do site
Google PageSpeed Insights — mobile performance audit of note-access-nj2w.rob-c2d.workers.dev · checked Apr 16, 2026
Você foi afetado por este site?
Se você inseriu credenciais de conta, informações pessoais ou de pagamento, ou baixou um arquivo deste domínio, tome medidas imediatas. Abaixo estão os recursos para ajudá-lo a relatar o incidente e se proteger.
Notifique as autoridades locais
Selecione seu país para obter contactos oficiais do cibercrime ou crie um rascunho de reclamação →.
Verificar qualquer domínio
Análise de ameaças usando lista de bloqueio armazenada, WHOIS, DNS e evidências de verificação pública
Digitalize agoraDenunciar phishing
Envie domínios suspeitos para nosso banco de dados de ameaças — proteja a comunidade
DenunciarFeed de ameaças em tempo real
Relatórios recentes de phishing e alterações de disponibilidade observadas
MonitorarMantenha-se informado, mantenha-se seguro
Monitore ameaças em tempo real ou conteste esta listagem caso acredite que se trate de um falso positivo