curly-violet-5dd4.jujuan98.workers[.]dev
Category: Phishing
To use full-featured product, you have to purchase a license for Combo Cleaner. Limited seven days free trial available. Combo Cleaner is owned and operated by RCS LT, the parent company of PCRisk.com.
Description of curly-violet-5dd4.jujuan98.workers[.]dev
The domain curly-violet-5dd4.jujuan98.workers[.]dev appears to be a subdomain hosted on a serverless web platform associated with Cloudflare Workers. Based on the hostname structure, it does not present itself as a conventional branded business website; instead, it looks more like a dynamically deployed application endpoint or temporary web service instance under a broader workers.dev environment.
Available classification data associates this URL with phishing-related activity, while one web-classification source also labels it as web hosting. That combination can occur when a cloud-hosted endpoint is used to serve transient content, redirects, or imitation login pages rather than a long-established public-facing website. No clear evidence in the provided scan indicates a legitimate organizational identity or transparent site operator for this specific subdomain.
Safety Assessment for curly-violet-5dd4.jujuan98.workers[.]dev
Multiple independent scan signals indicate elevated risk for this URL at the time of the scan. It was flagged by 11 out of 92 security engines, with most detections describing phishing-related behavior, and it was also categorized by multiple web-classification providers as phishing or fraud-related content. In addition, the URL was listed in a major safe-browsing database for social engineering, which is a strong indicator that the page may have been used to mislead visitors into disclosing credentials or other sensitive information.
Although one malware scan did not identify malicious files and reported no flagged scripts or external links, that does not outweigh the broader phishing-related consensus. Phishing pages often contain minimal code and may not trigger file-based malware detections, especially when the primary risk is deceptive content rather than malware delivery. The lack of external links or flagged files therefore should be interpreted cautiously.
Based on these findings, this website may pose potential risks to visitors at the time of this scan, particularly risks associated with phishing or social-engineering activity.
Technical Description
The site is hosted behind Cloudflare infrastructure and resolves to an IP address associated with Cloudflare in Toronto, Canada. It uses a valid TLS certificate issued by Google Trust Services, with expiration in July 2026. The domain is relatively old for a suspicious URL, but it is a subdomain under workers.dev, which can allow rapidly deployed hosted content that changes over time. The parent registration is with Cloudflare, Inc., and the nameservers are also on Cloudflare.
DNSSEC appears to be unsigned. No malware files, external links, or iframes were identified in the provided scan snapshot, but the stronger technical concern is the phishing consensus across security engines and blacklist data rather than exploit-heavy page behavior. The combination of cloud hosting, social-engineering listing, and multi-engine phishing detections suggests the endpoint may have been used for deceptive content at the time of analysis.
Share your experience with this website. Was it safe? Did you encounter any issues?