chrji-fhav-oz04[.]p-qtlv10l7[.]workers[.]dev
chrji-fhav-oz04.p-qtlv10l7.workers.dev — İçerik kullanılamıyor. Marka kimliğine bürünme: Generic; Dolandırıcılık türü: Crypto Drainer. Kanıt özeti: VirusTotal 10/94 (ADMINUSLabs, alphaMountain.ai, BitDefender, Chong Lua Dao, CyRadar); URLScan malicious verdict; PhishDestroy score 80/100. Kayıt kuruluşu: Cloudflare.
Özgün adli kaydı korumak için aşağıdaki ayrıntılı PhishDestroy AI analizi İngilizce bırakılmıştır.
PhishDestroy identifies chrji-fhav-oz04.workers.dev as an active crypto drainer targeting cryptocurrency users. This Workers.dev subdomain employs deceptive tactics to trick victims into connecting wallets and authorizing malicious transactions. The threat is elevated due to the immediate financial impact posed by unauthorized fund transfers. This domain was flagged by 9 out of 95 security vendors on VirusTotal, indicating widespread suspicion in the cybersecurity community. It resolves to IP 104.21.50.90, a Cloudflare Workers hosting environment commonly abused by threat actors for phishing infrastructure. The domain is registered through Cloudflare, Inc., leveraging their DNS and SSL services to appear legitimate. Using a Let's Encrypt SSL certificate, it mimics secure connections to increase trust. The Workers.dev subdomain structure is often chosen for its obscurity and rapid deployment capabilities, making detection and takedown more challenging. To mitigate risk, users must avoid interacting with this domain or any links associated with it. If you have visited chrji-fhav-oz04.workers.dev, disconnect your wallet immediately, revoke any unauthorized permissions, and transfer remaining funds to a secure wallet. Always verify URLs and use PhishDestroy’s real-time scanner before entering credentials or connecting wallets. Report this domain to PhishDestroy to aid in blocking efforts and protect others from potential harm.
Tehdit Müdahale Pipeline
Genel Engelleme Listesi Durumu
Teknolojiler · 3 identified
HTTP Strict Transport Security (HSTS) informs browsers that the site should only be accessed using HTTPS.
www.rfc-editor.org %100 güvenCloudflare is a web-infrastructure and website-security company, providing content-delivery-network services, DDoS mitigation, Internet security, and distributed domain-name-server services.
www.cloudflare.com %100 güvenHTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org %100 güvenVirusTotal Analizi
Arşivlenmiş Kanıtlar
Site Performans Analizi
Google PageSpeed Insights — mobile performance audit of chrji-fhav-oz04.p-qtlv10l7.workers.dev · checked Apr 23, 2026
Kanıtlar ve Dış Raporlar
Bu Siteden Etkilendiniz mi?
Hesap kimlik bilgilerini, kişisel bilgileri veya ödeme bilgilerini girdiyseniz ya da bu alan adından bir dosya indirdiyseniz hemen harekete geçin. Aşağıda olayı bildirmenize ve kendinizi korumanıza yardımcı olacak kaynaklar bulunmaktadır.
Yerel Yetkililere Bildirin
resmi siber suç iletişim bilgileri veya şikayet taslağı oluştur → almak için ülkenizi seçin.
Herhangi Bir Alan Adını Kontrol Et
Saklanan engelleme listesi, WHOIS, DNS ve genel tarama kanıtlarını kullanarak tehdit analizi
Şimdi TaraOltalama Olayını Bildir
Şüpheli alan adlarını tehdit veritabanımıza bildirin — topluluğu koruyun
BildirCanlı Tehdit Akışı
Son kimlik avı raporları ve gözlemlenen kullanılabilirlik değişiklikleri
İzleGelişmelerden Haberdar Olun, Güvende Kalın
Canlı tehditleri izleyin veya bunun yanlış bir uyarı olduğunu düşünüyorsanız bu kayda itiraz edin