hfjrk-jgcg-xrna[.]c-2xtasw30[.]workers[.]dev
hfjrk-jgcg-xrna.c-2xtasw30.workers.dev — Контент недоступний. Уособлення бренду: Cloudflare; Тип шахрайства: Brand Impersonation. Зведення доказів: VirusTotal 15/91 (ADMINUSLabs, Criminal IP, alphaMountain.ai, BitDefender, CyRadar); URLScan malicious verdict; PhishDestroy score 100/100. Реєстратор: Cloudflare.
Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.
This domain, hfjrk-jgcg-xrna.c-2xtasw30.workers.dev, is currently operating as an active generic phishing endpoint. Analysis indicates the infrastructure is designed to facilitate credential harvesting or malicious payload delivery, though no specific brand impersonation has been confirmed at this time. The site remains accessible and exhibits characteristics consistent with phishing campaigns, including a blank or loading page title, which is often used to evade initial detection while awaiting dynamic content injection. Infrastructure analysis reveals the domain was registered through Cloudflare, Inc. on April 28, 2026, and resolves to the IP address 188.114.97.3, located in Canada and associated with Cloudflare's network. The domain is flagged by 15 of 95 security vendors on VirusTotal, indicating moderate to high confidence in its malicious nature. It appears on at least one security blocklist and is actively blocked by enterprise phishing detection systems. The SSL certificate is issued by Let's Encrypt (serial number E8), a common choice for both legitimate and malicious sites due to its ease of acquisition and short-lived validity periods. The current status of this domain is active, with no signs of takedown or mitigation as of this report. Organizations and individuals are advised to block traffic to this domain at the network level, including its resolving IP address. Security teams should monitor for connections to 188.114.97.3 and the domain itself in logs, particularly those associated with user-initiated web traffic. Endpoint protection solutions should be updated to include this domain in phishing and malicious URL databases. Given the domain's hosting on Cloudflare Workers, which allows for rapid deployment and obfuscation, continuous monitoring for related subdomains or newly generated Worker routes is recommended.
Процес реагування на загрози Pipeline
Статус у публічних блоклистах
Збережений знімок
Аналітика доменів
Технічні деталіDNS, SAN-адреси SSL, мітки часу
Аналіз VirusTotal
Аналіз продуктивності сайту
Google PageSpeed Insights — mobile performance audit of hfjrk-jgcg-xrna.c-2xtasw30.workers.dev · checked Apr 29, 2026
Докази та зовнішні звіти
Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога