vlpzh-tcga-w7f4[.]c-o8e5spbn[.]workers[.]dev
vlpzh-tcga-w7f4.c-o8e5spbn.workers.dev — Неперевірений. Тип шахрайства: Credential Phishing. Зведення доказів: VirusTotal 12/91 (ADMINUSLabs, Criminal IP, BitDefender, CyRadar, ESET); PhishDestroy score 93/100. Реєстратор: Cloudflare Workers.
Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.
This domain, vlpzh-tcga-w7f4.c-o8e5spbn.workers.dev, was registered on 14 May 2026 and is hosted on Cloudflare Workers infrastructure, resolving to IP 188.114.96.3 located in the Cloudflare network. The site presents a valid TLS certificate issued by Let’s Encrypt (E8) and returns HTTP 200 responses with the page title “Loading…”. VirusTotal scans show 11 of 92 security vendors flag the domain, and Gridinsoft assigns a trust score of 0/100, indicating a high likelihood of malicious use. The domain is currently listed on one public blocklist and is actively blocked by PhishDestroy. Intelligence classifies the activity as credential phishing, targeting user credentials, though the specific lure or victim profile has not been observed. The short lifespan, recent creation date, and use of a workers.dev subdomain are consistent with disposable phishing infrastructure. Defenders should add the fully qualified domain name to deny‑list rules across DNS, proxy, and web‑filter solutions, and ensure that TLS inspection policies do not inadvertently allow the encrypted traffic. Continuous monitoring of the associated IP address and any related workers.dev subdomains is recommended, as threat actors may reuse the same edge node for future campaigns. Because the visible page content is limited to the generic “Loading…” title, further automated crawling or sandbox analysis is advised to capture any credential‑collection forms that may be served after initial load. Organizations should also educate users about unexpected login prompts and enforce multi‑factor authentication to mitigate credential compromise risk.
Процес реагування на загрози Pipeline
Статус у публічних блоклистах
Аналітика доменів
Технічні деталіDNS, SAN-адреси SSL, мітки часу
Аналіз VirusTotal
Докази та зовнішні звіти
Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога