adobe-4s9[.]kpenza-htrenchless-com-s-account[.]workers[.]dev
“Worker threw exception | adobe-4s9.kpenza-htrenchless-com-s-account.workers.dev | Cloudflare”
adobe-4s9.kpenza-htrenchless-com-s-account.workers.dev — 未验证. 品牌冒充:Adobe; 诈骗类型:Brand Impersonation. 证据摘要: VirusTotal 16/91 (ADMINUSLabs, Criminal IP, alphaMountain.ai, BitDefender, Chong Lua Dao); PhishDestroy score 95/100. 注册商: Cloudflare Workers.
为保留原始取证记录,下方的 PhishDestroy AI 详细分析仍使用英文。
The domain adobe-4s9.kpenza-htrenchless-com-s-account.workers.dev actively impersonates Adobe to conduct phishing attacks. It is hosted by Cloudflare and has been flagged as malicious by 17 out of 95 vendors on VirusTotal. This indicates a significant level of detection, suggesting the domain's phishing activities are recognized by many security solutions.
This domain is registered through Cloudflare Workers and utilizes Let's Encrypt for its SSL certificate. Such infrastructure choices are common among phishing operations due to their ease of setup and the credibility they lend to malicious sites. The domain's hosting IP, 104.21.96.51, is located in Canada and is part of Cloudflare's network, which provides robust performance and anonymity for the operators.
PhishDestroy has included this domain in its public blocklist, highlighting its threat level. The domain's creation date in 2026 raises questions about the accuracy of registration data, possibly indicating an attempt to obfuscate its true age and activity timeline. This tactic could be used to mislead security researchers and automated detection systems.
Overall, the domain's activity and detection by multiple security vendors underscore the importance of recognizing and mitigating phishing threats quickly. The use of Adobe's brand in this phishing scheme likely aims to exploit users' trust in the well-known software company, making it crucial for potential victims to verify the authenticity of any communication or site purporting to be from Adobe.
威胁响应 Pipeline
公共封禁名单状态
域名情报
技术细节DNS、SSL SAN、时间戳
VirusTotal 分析
证据与外部报告
您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。