voice-mail-auth-office-com[.]saxeco7653[.]workers[.]dev
“Suspected Phishing | Cloudflare”
voice-mail-auth-office-com.saxeco7653.workers.dev — Conteúdo indisponível. Representação da marca: Google. Resumo das evidências: VirusTotal 14/91 (ADMINUSLabs, Criminal IP, BitDefender, Chong Lua Dao, CyRadar); URLScan malicious verdict; CF Radar malicious; PhishDestroy score 92/100. Registrador: Cloudflare.
A análise detalhada do PhishDestroy AI permanece em inglês para preservar o registro forense original.
The domain voice-mail-auth-office-com.saxeco7653.workers.dev is currently active and classified as a generic phishing campaign. Infrastructure analysis shows the hostname resolves to the IPv4 address 188.114.97.3. The IP belongs to a hosting provider that frequently serves Cloudflare‑protected resources, and the domain was registered through Cloudflare, Inc., indicating use of the provider’s domain privacy and rapid provisioning services. TLS termination is performed by Google Trust Services, which supplies a valid certificate for the host, thereby giving the site a legitimate‑looking HTTPS indicator in browsers. On VirusTotal the domain received detections from 14 of 91 scanning engines, confirming that multiple security products consider the host malicious.
The domain is listed on a single external blocklist and is actively blocked by the PhishDestroy filtering service. Nameserver information could not be retrieved, suggesting that the authoritative records are either hidden behind Cloudflare’s proxy or were not exposed at the time of analysis. No additional intelligence such as page title, Safe Browsing status, or content hashes is available, leaving the exact phishing lure and targeted brand undefined. Defenders should treat any traffic to this host as malicious. Immediate actions include adding the domain and its resolving IP address to outbound deny lists, ensuring that DNS filtering solutions block the domain, and confirming that web proxy rules reject HTTPS connections to the host regardless of certificate validity.
Monitoring for other subdomains that resolve to the same IP, as well as for new domains registered through Cloudflare, can help uncover related infrastructure. Because the certificate is issued by a widely trusted CA, standard TLS inspection may be required to reveal the underlying payload. Organizations should also share the indicator set with threat‑intel platforms to improve community detection.
Inteligência de segurança de rede
Pipeline de resposta a ameaças
Status da lista de bloqueios pública
Captura armazenada
Inteligência de Domínios
Detalhes técnicosDNS, SANs do SSL, carimbos de data e hora
Tecnologias · 3 identified
HTTP Strict Transport Security (HSTS) informs browsers that the site should only be accessed using HTTPS.
www.rfc-editor.org 100% de confiançaCloudflare is a web-infrastructure and website-security company, providing content-delivery-network services, DDoS mitigation, Internet security, and distributed domain-name-server services.
www.cloudflare.com 100% de confiançaHTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org 100% de confiançaAnálise do VirusTotal
Análise de desempenho do site
Google PageSpeed Insights — mobile performance audit of voice-mail-auth-office-com.saxeco7653.workers.dev · checked Jul 29, 2026
Evidências e relatórios externos
Você foi afetado por este site?
Se você inseriu credenciais de conta, informações pessoais ou de pagamento, ou baixou um arquivo deste domínio, tome medidas imediatas. Abaixo estão os recursos para ajudá-lo a relatar o incidente e se proteger.
Notifique as autoridades locais
Selecione seu país para obter contactos oficiais do cibercrime ou crie um rascunho de reclamação →.
Verificar qualquer domínio
Análise de ameaças usando lista de bloqueio armazenada, WHOIS, DNS e evidências de verificação pública
Digitalize agoraDenunciar phishing
Envie domínios suspeitos para nosso banco de dados de ameaças — proteja a comunidade
DenunciarFeed de ameaças em tempo real
Relatórios recentes de phishing e alterações de disponibilidade observadas
MonitorarMantenha-se informado, mantenha-se seguro
Monitore ameaças em tempo real ou conteste esta listagem caso acredite que se trate de um falso positivo