vaeg-8bcp-7bkr[.]tgopaul-foundrymortgagecapital-com-s-account[.]workers[.]dev
“vaeg-8bcp-7bkr.tgopaul-foundrymortgagecapital-com-s-account.workers.dev”
vaeg-8bcp-7bkr.tgopaul-foundrymortgagecapital-com-s-account.workers.dev — Неперевірений. Зведення доказів: VirusTotal 14/91 (ADMINUSLabs, BitDefender, Chong Lua Dao, CyRadar, ESET); PhishDestroy score 93/100. Реєстратор: Cloudflare.
Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.
The domain vaeg-8bcp-7bkr.tgopaul-foundrymortgagecapital-com-s-account.workers.dev is identified as a phishing threat, with 12 out of 91 VirusTotal vendors marking it as malicious. It is currently active and hosted on an IP address in the United States under Cloudflare, Inc. The domain is also listed on two public blocklists, including PhishDestroy and OpenPhish, indicating its recognition as a threat.
This domain operates under the guise of a legitimate service, potentially targeting users with phishing attacks aimed at stealing sensitive information. The SSL certificate is issued by Let's Encrypt, which is commonly used for legitimate sites but can also be exploited by malicious actors to create a false sense of security. The platform risk score is notably high at 93 out of 100, underscoring the potential danger it poses to unsuspecting users.
Despite its recent detection on June 22, 2026, the domain's malicious activity has been swiftly identified by multiple security vendors. This rapid detection highlights the effectiveness of collaborative threat intelligence efforts in identifying and mitigating phishing threats. The use of Cloudflare's infrastructure suggests an attempt to leverage reputable services to enhance the credibility of the phishing operation.
Overall, the domain vaeg-8bcp-7bkr.tgopaul-foundrymortgagecapital-com-s-account.workers.dev exemplifies a sophisticated phishing scheme, utilizing both advanced hosting services and SSL encryption to deceive users. Its presence on public blocklists and the high risk score should prompt immediate caution for any potential interactions with this domain.
Процес реагування на загрози Pipeline
Статус у публічних блоклистах
Технології · 3 identified
HTTP Strict Transport Security (HSTS) informs browsers that the site should only be accessed using HTTPS.
www.rfc-editor.org 100% впевненостіCloudflare is a web-infrastructure and website-security company, providing content-delivery-network services, DDoS mitigation, Internet security, and distributed domain-name-server services.
www.cloudflare.com 100% впевненостіHTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org 100% впевненостіАналіз VirusTotal
Докази та зовнішні звіти
Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога