hemat138[.]mamamudah559[.]workers[.]dev
“HEMAT138 : Situs Slot Gacor Gampang Menang Online Hari Ini”
证据摘要
PhishDestroy identifies hemat138.mamamudah559.workers.dev as an active phishing domain impersonating a login portal, likely targeting credential theft. This Workers.dev subdomain resolves to IP 188.114.96.3 and leverages a Google Trust Services SSL certificate to appear legitimate. The domain currently shows zero detections on VirusTotal (1/95 engines), suggesting it evades traditional antivirus tools but remains under investigation by security researchers. Registered through Cloudflare, Inc., the domain’s Workers.dev platform association further complicates tracking due to Cloudflare’s masking of underlying infrastructure. This domain exhibits clear phishing indicators, including a deceptive Workers.dev subdomain (mamamudah559) designed to mimic a trusted service. The combination of a Google-issued SSL certificate and Cloudflare’s infrastructure adds a veneer of authenticity, tricking users into entering sensitive credentials. With no current blocklist detections, the threat remains undetected by most security tools, increasing the risk of successful phishing campaigns. The seed identifier 6dd2d1 suggests this is part of a larger, evolving campaign. Users who visited hemat138.mamamudah559.workers.dev should immediately check their browser history for unauthorized logins and revoke any exposed credentials. If credentials were entered, change passwords on all accounts using the same login details and enable multi-factor authentication where possible. Report the domain to your IT administrator or security team and avoid interacting with similar Workers.dev subdomains. Use a reputable ad-blocker or DNS filtering service to block known malicious domains proactively.
Data Coverage
网络安全情报
威胁响应 Pipeline
阻止列表覆盖
监控中的外部数据源 10 个 · 已存快照 2026年8月13日
技术
识别出 5 项高置信度技术
VirusTotal 分析
网站性能分析
Google PageSpeed Insights — mobile performance audit of hemat138.mamamudah559.workers.dev · checked May 3, 2026
您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。
检查任意域名
使用存储的阻止列表、WHOIS、DNS 和公共扫描证据进行威胁分析
立即扫描举报网络钓鱼
将可疑域名提交至我们的威胁数据库——保护社区
报告实时威胁动态
最近的网络钓鱼报告和观察到的可用性变化
监控