3d446d67[.]mewjdjckc-0sbbc83hhzxsh[.]pages[.]dev
“Worker threw exception | 3d446d67.mewjdjckc-0sbbc83hhzxsh.pages.dev | Cloudflare”
3d446d67.mewjdjckc-0sbbc83hhzxsh.pages.dev — Doğrulanmamış. Marka kimliğine bürünme: Cloudflare; Dolandırıcılık türü: Brand Impersonation. Kanıt özeti: VirusTotal 2/91 (alphaMountain.ai, Forcepoint ThreatSeeker); PhishDestroy score 76/100. Kayıt kuruluşu: Cloudflare.
Özgün adli kaydı korumak için aşağıdaki ayrıntılı PhishDestroy AI analizi İngilizce bırakılmıştır.
This domain, 3d446d67.mewjdjckc-0sbbc83hhzxsh.pages.dev, is flagged as an active brand impersonation threat targeting Cloudflare. Registered on February 21, 2026, through Cloudflare, Inc., it resolves to the IP 104.21.80.1 (AS13335, Cloudflare, Inc.) and is hosted within Cloudflare's infrastructure. The page title, 'Worker threw exception | 3d446d67.mewjdjckc-0sbbc83hhzxsh.pages.dev | Cloudflare,' explicitly references Cloudflare, reinforcing the impersonation classification. Analysis indicates the domain is currently returning an HTTP 500 status, which may suggest either a misconfigured phishing kit or an attempt to evade detection by presenting as a broken service. Technical indicators include the use of Cloudflare's Pages platform, HSTS, and HTTP/3, aligning with legitimate Cloudflare-hosted services but also providing cover for malicious activity. The SSL certificate is issued by Google Trust Services (WE1), a common certificate authority, which does not inherently indicate malicious intent. Two of 93 security vendors on VirusTotal have flagged this domain, and it appears on at least one security blocklist, including PhishDestroy. The domain's Gridinsoft trust score is 0/100, further supporting its classification as high-risk. Defenders should treat this domain as part of a Cloudflare impersonation campaign. The use of Cloudflare's own infrastructure complicates detection, as traffic and hosting patterns may blend with legitimate services. Network-level blocking of the domain and its resolving IP (104.21.80.1) is recommended, alongside monitoring for similar patterns in subdomains under *.pages.dev. Additional analysis of the domain's historical content or redirects, if available, may provide further context on the specific phishing tactics employed. The domain remains active as of July 12, 2026, and should be considered a live threat.
Tehdit Müdahale Pipeline
Genel Engelleme Listesi Durumu
Teknolojiler · 3 identified
HTTP Strict Transport Security — forces browsers to use HTTPS connections only.
Web infrastructure and security company providing CDN, DDoS mitigation, and DNS services.
www.cloudflare.comThird major version of HTTP protocol, built on QUIC for faster, more reliable connections.
VirusTotal Analizi
Kanıtlar ve Dış Raporlar
Bu Siteden Etkilendiniz mi?
Hesap kimlik bilgilerini, kişisel bilgileri veya ödeme bilgilerini girdiyseniz ya da bu alan adından bir dosya indirdiyseniz hemen harekete geçin. Aşağıda olayı bildirmenize ve kendinizi korumanıza yardımcı olacak kaynaklar bulunmaktadır.
Yerel Yetkililere Bildirin
resmi siber suç iletişim bilgileri veya şikayet taslağı oluştur → almak için ülkenizi seçin.
Herhangi Bir Alan Adını Kontrol Et
Saklanan engelleme listesi, WHOIS, DNS ve genel tarama kanıtlarını kullanarak tehdit analizi
Şimdi TaraOltalama Olayını Bildir
Şüpheli alan adlarını tehdit veritabanımıza bildirin — topluluğu koruyun
BildirCanlı Tehdit Akışı
Son kimlik avı raporları ve gözlemlenen kullanılabilirlik değişiklikleri
İzleGelişmelerden Haberdar Olun, Güvende Kalın
Canlı tehditleri izleyin veya bunun yanlış bir uyarı olduğunu düşünüyorsanız bu kayda itiraz edin