my-workeruni001[.]trubogibvitalya228[.]workers[.]dev
my-workeruni001.trubogibvitalya228.workers.dev — 未验证. 证据摘要: VirusTotal 2/91 (alphaMountain.ai, Forcepoint ThreatSeeker); PhishDestroy score 76/100. 注册商: Cloudflare.
为保留原始取证记录,下方的 PhishDestroy AI 详细分析仍使用英文。
This domain is flagged as a high-risk credential harvesting phishing endpoint targeting corporate and personal account credentials. Analysis indicates the infrastructure is designed to mimic legitimate login portals, likely deploying cloned authentication interfaces to capture usernames, passwords, and multi-factor authentication tokens. The domain exhibits characteristics consistent with targeted phishing campaigns, including the use of subdomain obfuscation and rapid deployment on edge computing platforms to evade detection. Infrastructure analysis reveals the domain was registered through Cloudflare, Inc. on June 11, 2026, and currently resolves to the IP address 188.114.96.3. Security vendor assessments show 2 out of 95 engines on VirusTotal flag the domain as malicious, while it appears on one security blocklist. The SSL certificate, issued by Google Trust Services (WE1), confirms the domain is actively deployed and configured to establish encrypted connections, a common tactic to lend false legitimacy to phishing pages. The domain remains operational despite partial detection, indicating ongoing threat activity. Users who have visited my-workeruni001.trubogibvitalya228.workers.dev or entered credentials on any page hosted under this domain should immediately reset passwords for all potentially compromised accounts, particularly those linked to corporate or financial services. Enable multi-factor authentication where available, and review account activity for unauthorized access or transactions. Security teams should block the domain and its resolving IP address (188.114.96.3) at the network perimeter, and monitor for indicators of compromise such as unusual login attempts or data exfiltration patterns. If credentials were submitted, assume they are compromised and initiate incident response protocols.
威胁响应 Pipeline
公共封禁名单状态
VirusTotal 分析
证据与外部报告
您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。