linktron84[.]worker-6ffadacf[.]workers[.]dev
“Coming Soon”
已存储的观测记录
观测到的标题差异
证据摘要
linktron84.worker-6ffadacf.workers.dev was observed as an offline site that has been classified as a crypto‑scam phishing domain. The domain resolves to 172.67.165.248, an address owned by AS13335 Cloudflare, Inc. in the United States. DNS resolution uses the Cloudflare authoritative nameservers clyde.ns.cloudflare.com and sofia.ns.cloudflare.com, confirming that the registrar is Cloudflare, Inc. The TLS certificate presented is issued by Google Trust Services under the WE1 intermediate, indicating that HTTPS is correctly configured despite the site being unavailable. HTTP headers report HSTS enforcement and support for HTTP/3, both typical of Cloudflare‑protected services.
A request to the root URL returns HTTP 404, and the only visible page title is “Coming Soon”, suggesting that no malicious payload is currently served. VirusTotal analysis recorded a single positive detection out of 93 security vendors, and the domain appears on one external blocklist, where it is listed by PhishDestroy as a malicious resource. The domain was created on 08 February 2019, and no further changes to its registration have been reported. The available intelligence points to a typical abuse pattern: a Cloudflare‑hosted domain, using a valid SSL certificate, and previously flagged for crypto‑related phishing.
Because the site is offline, active exploitation cannot be confirmed, but the presence of a positive vendor detection and blocklist entry indicates a residual risk. Defenders should continue to block the domain at DNS and proxy layers, monitor the associated IP address for any resurgence of malicious activity, and consider adding the domain to internal threat‑intel feeds. Ongoing observation of the Cloudflare nameservers for new subdomains is also recommended.
Data Coverage
威胁响应 Pipeline
阻止列表覆盖
监控中的外部数据源 10 个 · 已存快照 2026年8月11日
检测时间线
技术
识别出 3 项高置信度技术
VirusTotal 分析
您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。
检查任意域名
使用存储的阻止列表、WHOIS、DNS 和公共扫描证据进行威胁分析
立即扫描举报网络钓鱼
将可疑域名提交至我们的威胁数据库——保护社区
报告实时威胁动态
最近的网络钓鱼报告和观察到的可用性变化
监控