2dzl-umko-ou34.tom-macsystemsltd-co-uk-s-account.workers.dev
Category: Phishing
To use full-featured product, you have to purchase a license for Combo Cleaner. Limited seven days free trial available. Combo Cleaner is owned and operated by RCS LT, the parent company of PCRisk.com.
Description of 2dzl-umko-ou34.tom-macsystemsltd-co-uk-s-account.workers.dev
This domain appears to be a Cloudflare Workers-hosted page rather than a conventional standalone business website. The visible content presents itself as a "SharePoint File Share" or file-review portal and uses Microsoft-themed branding, suggesting that it is attempting to imitate a document-sharing or identity-verification workflow associated with Microsoft services.
Based on the domain structure, the page does not appear to be an official Microsoft or SharePoint property. Instead, it uses a long subdomain under workers.dev, which is commonly used for quickly deployed web applications and temporary pages. The combination of a generic file-access prompt, identity-verification messaging, and Microsoft-style interface elements may indicate that the page is designed to capture user interaction under the appearance of a familiar cloud-service login flow.
Safety Assessment for 2dzl-umko-ou34.tom-macsystemsltd-co-uk-s-account.workers.dev
Multiple security signals indicate elevated risk at the time of this scan. The domain was flagged by 15 out of 91 security engines, and several web-classification sources categorized it as phishing, fraud, or malicious. In the screenshot, the page closely imitates a Microsoft SharePoint file-sharing screen and encourages the visitor to continue to Microsoft after copying a verification code, which may be consistent with credential-harvesting or social-engineering behavior.
Although the malware scan did not detect malicious files on the page itself, that does not outweigh the broader phishing indicators. In addition, the domain's IP address is listed on one mail-reputation blocklist, which is a weaker signal on its own but still worth noting. The domain is several years old, but the specific workers.dev subdomain can still be created and repurposed quickly, so age of the parent registration does not substantially reduce concern here.
Based on these findings, this website may pose potential risks to visitors.
Technical Description
The site is served over HTTPS with a valid TLS certificate issued by a mainstream certificate authority, and it is hosted behind Cloudflare infrastructure on a Cloudflare IP address in Toronto, Canada. The web server appears to be Cloudflare, and the domain uses Cloudflare nameservers. DNSSEC is not enabled for the domain based on the available data.
From a security perspective, the presence of valid SSL/TLS should not be treated as proof of legitimacy, since phishing pages commonly use HTTPS as well. The use of a workers.dev deployment suggests serverless hosting, which can make rapid setup and takedown easier. No malicious files, external links, or iframes were identified in the provided page scan, but the page's presentation and reputation signals remain the primary concerns at the time of this scan.
Share your experience with this website. Was it safe? Did you encounter any issues?