index-546[.]hank-andrews-verusresearchs-net-s-account[.]workers[.]dev
“Worker threw exception | index-546.hank-andrews-verusresearchs-net-s-account.workers.dev | Cloudfla…”
index-546.hank-andrews-verusresearchs-net-s-account.workers.dev — 未验证. 品牌冒充:Cloudflare; 诈骗类型:Brand Impersonation. 证据摘要: VirusTotal 15/91 (ADMINUSLabs, Criminal IP, BitDefender, Chong Lua Dao, CyRadar); PhishDestroy score 95/100. 注册商: Cloudflare Workers.
为保留原始取证记录,下方的 PhishDestroy AI 详细分析仍使用英文。
This domain, index-546.hank-andrews-verusresearchs-net-s-account.workers.dev, is an active credential phishing threat designed to harvest user login credentials through fraudulent authentication interfaces. Analysis indicates the domain specifically targets individuals by impersonating legitimate services, likely leveraging social engineering tactics to deceive victims into submitting sensitive information. The domain is currently operational and has not been taken down despite security detections. Infrastructure analysis reveals the domain is registered through Cloudflare Workers and resolves to the IP address 188.114.96.3, located in Canada under Cloudflare, Inc. It was created on May 02, 2026, though this date may reflect automated registration processes rather than typical domain lifecycle timelines. The domain is flagged by 16 of 95 security vendors on VirusTotal, with a Let's Encrypt SSL certificate (serial number E7) providing HTTPS encryption to lend false legitimacy. It appears on one security blocklist, specifically PhishDestroy, and displays a Cloudflare Worker exception error, suggesting either misconfiguration or evasion attempts. The risk level for this domain is classified as high due to its active status, credential harvesting intent, and use of reputable hosting infrastructure to bypass initial scrutiny. Organizations and individuals are advised to block the domain at the network level and add the IP address 188.114.96.3 to firewall deny lists. Security teams should monitor for any attempts to access this domain from internal networks and conduct user awareness training to recognize phishing indicators, such as unusual subdomain structures and Cloudflare Worker-based URLs. Endpoint protection systems should be updated to include this domain in real-time threat intelligence feeds to prevent potential data breaches.
威胁响应 Pipeline
公共封禁名单状态
域名情报
技术细节DNS、SSL SAN、时间戳
VirusTotal 分析
证据与外部报告
您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。