lingering-frog-e644[.]fgniselbnsaojvfmceeosig[.]workers[.]dev
“Worker threw exception | lingering-frog-e644.fgniselbnsaojvfmceeosig.workers.dev | Cloudflare”
lingering-frog-e644.fgniselbnsaojvfmceeosig.workers.dev — 未验证. 品牌冒充:Cloudflare; 诈骗类型:Generic Phishing. 证据摘要: VirusTotal 14/91 (ADMINUSLabs, Criminal IP, alphaMountain.ai, BitDefender, Chong Lua Dao); PhishDestroy score 93/100. 注册商: Cloudflare Workers.
为保留原始取证记录,下方的 PhishDestroy AI 详细分析仍使用英文。
The domain lingering-frog-e644.fgniselbnsaojvfmceeosig.workers.dev is identified as an active generic phishing threat designed to harvest user credentials through deceptive web interfaces. Analysis indicates the domain leverages Cloudflare Workers infrastructure to host malicious content, with no specific brand impersonation detected at this stage. The threat primarily relies on obfuscated JavaScript and exception-handling redirections to evade detection while capturing sensitive login data. Infrastructure analysis reveals the domain was registered through Cloudflare Workers on April 18, 2026, and currently resolves to the IP address 188.114.96.3, geolocated to Canada under Cloudflare, Inc. Detection metrics show the domain is flagged by 12 of 95 security vendors on VirusTotal, with a single entry on operational blocklists. The SSL certificate, issued by Let's Encrypt (serial number E7), provides encrypted connections to further legitimize the phishing attempt. The page title, 'Worker threw exception,' suggests deliberate use of error-based redirection techniques to mask malicious activity. As of the latest assessment, the domain remains active and continues to pose a high-risk threat to users. Organizations and individuals are advised to block the domain and its associated IP (188.114.96.3) at the network level. Security teams should monitor for anomalous worker script deployments on Cloudflare infrastructure and implement real-time phishing detection mechanisms. End-users should verify domain legitimacy before entering credentials, particularly on platforms hosted via content delivery networks.
威胁响应 Pipeline
公共封禁名单状态
域名情报
技术细节DNS、SSL SAN、时间戳
VirusTotal 分析
证据与外部报告
您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。