urlshort-linkmqnzgonvyhlm[.]askonyuh[.]workers[.]dev
“Suspected Phishing | Cloudflare”
urlshort-linkmqnzgonvyhlm.askonyuh.workers.dev — Неперевірений. Уособлення бренду: Cloudflare; Тип шахрайства: Brand Impersonation. Зведення доказів: VirusTotal 5/91 (BitDefender, ESET, Forcepoint ThreatSeeker, G-Data, Webroot); URLScan malicious verdict; PhishDestroy score 76/100. Реєстратор: Cloudflare.
Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.
This domain, urlshort-linkmqnzgonvyhlm.askonyuh.workers.dev, is actively impersonating Cloudflare as part of a high-risk phishing operation. Registered on June 23, 2026, through Cloudflare, Inc., the domain resolves to IP address 188.114.97.3 and is currently flagged by at least one security blocklist, including PhishDestroy. The page title explicitly references Cloudflare, stating 'Suspected Phishing | Cloudflare,' which aligns with the identified brand impersonation threat type. Infrastructure analysis reveals the use of Cloudflare-hosted services, including Workers.dev, alongside standard web technologies such as Tailwind CSS, HSTS, and HTTP/3. The SSL certificate is issued by Google Trust Services, a common practice for both legitimate and malicious domains. Two out of ninety-five security vendors on VirusTotal have flagged this domain, though the specific detection context remains unverified. The domain's trust score is 0/100, reinforcing its suspicious status. While the exact content and functionality of the site have not been analyzed, the available indicators—such as the page title, registration details, and hosting infrastructure—strongly suggest an intent to deceive users by mimicking Cloudflare's branding. Defenders should treat this domain as malicious and prioritize blocking or monitoring access to it. Additional investigation into associated infrastructure, such as resolving IP addresses or related domains, may provide further context for mitigation efforts.
Процес реагування на загрози Pipeline
Статус у публічних блоклистах
Технології · 4 identified
HTTP Strict Transport Security (HSTS) informs browsers that the site should only be accessed using HTTPS.
www.rfc-editor.org 100% впевненостіCloudflare is a web-infrastructure and website-security company, providing content-delivery-network services, DDoS mitigation, Internet security, and distributed domain-name-server services.
www.cloudflare.com 100% впевненостіHTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org 100% впевненостіАналіз VirusTotal
Архівні докази
Докази та зовнішні звіти
Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога