mail-link-zkfq[.]p-qjt4uz2n[.]workers[.]dev
mail-link-zkfq.p-qjt4uz2n.workers.dev — 内容不可用. 品牌冒充:Generic; 诈骗类型:Credential Phishing. 证据摘要: VirusTotal 9/94 (ADMINUSLabs, alphaMountain.ai, CyRadar, ESET, G-Data); URLScan malicious verdict; PhishDestroy score 77/100. 注册商: Cloudflare.
为保留原始取证记录,下方的 PhishDestroy AI 详细分析仍使用英文。
PhishDestroy identifies an active credential harvesting campaign on the domain mail-link-zkfq.p-qjt4uz2n.workers.dev. This domain is currently hosting a phishing page designed to steal user credentials under the guise of a legitimate service. The threat is classified as high risk due to its active status and the presence of multiple indicators of compromise, including SSL certificates and blocklist presence.
This domain was flagged by 9 of 95 VirusTotal security vendors, indicating a significant level of suspicion. It resolves to the IP address 188.114.97.3 and is registered through Cloudflare, Inc. The domain appears on 1 active security blocklist and holds a Let's Encrypt SSL certificate, which may be used to deceive users into believing the site is trustworthy. The page title remains generic, displaying only 'Loading...' to avoid immediate detection while the malicious content loads dynamically.
The current status of this domain is active, and it continues to pose a threat to unsuspecting users. PhishDestroy recommends blocking this domain at the network level and avoiding any interaction with it. Users who may have entered credentials on this site should immediately change their passwords and enable multi-factor authentication where possible. Organizations are advised to update their threat intelligence feeds and firewall rules to include this domain and its associated IP address for proactive defense.
威胁响应 Pipeline
公共封禁名单状态
VirusTotal 分析
网站性能分析
Google PageSpeed Insights — mobile performance audit of mail-link-zkfq.p-qjt4uz2n.workers.dev · checked Apr 22, 2026
证据与外部报告
您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。