jieyo-ohdk-45jv.c-01md9x3b.workers[.]dev
Category: Phishing
To use full-featured product, you have to purchase a license for Combo Cleaner. Limited seven days free trial available. Combo Cleaner is owned and operated by RCS LT, the parent company of PCRisk.com.
Description of jieyo-ohdk-45jv.c-01md9x3b.workers[.]dev
This domain appears to be a subdomain hosted on a cloud edge platform under the workers.dev namespace, which is commonly used to deploy lightweight web applications, redirects, APIs, and temporary web content. The hostname itself is highly random-looking and does not indicate a recognizable brand, organization, or public-facing service, which can make it difficult to associate with a legitimate business purpose based on the domain name alone.
Based on the available scan context, there is no clear evidence of a conventional corporate website, publisher, retailer, or established online service operating at this address. Instead, it appears more consistent with an ephemeral or custom-hosted endpoint delivered through shared cloud infrastructure, where individual subdomains may be created and removed quickly by users of the platform.
Safety Assessment for jieyo-ohdk-45jv.c-01md9x3b.workers[.]dev
Multiple security engines flagged this URL at the time of the scan, with 17 out of 94 reporting phishing, malicious, or suspicious classifications. That level of agreement is a meaningful warning sign, especially for a workers.dev subdomain with a random-looking label and no established reputation or ranking. Although one malware scan did not detect malicious files and several blacklist databases did not list the URL at the time of review, those clean results do not outweigh the concentration of phishing-related detections.
The domain is also not ranked among popular sites, and the hostname structure may be consistent with disposable or short-lived infrastructure sometimes used for deceptive campaigns. Because this is a hosted subdomain on shared cloud infrastructure, the underlying platform itself is not the issue; rather, the concern relates to the specific subdomain and how it may be being used.
Based on these findings, this website may pose potential risks to visitors.
Technical Description
The site was served through Cloudflare infrastructure and presented a valid Let's Encrypt SSL certificate at the time of the scan. HTTPS availability indicates encrypted transport, but this should not be interpreted as proof of legitimacy, since low-cost or automated certificates are widely available to both legitimate and abusive sites. The server resolved to a Cloudflare IP in Toronto, Canada, and the web server was identified as Cloudflare.
WHOIS data indicates the parent domain registration has existed for several years and is managed by Cloudflare, Inc., but this is less informative than usual because the scanned host is a workers.dev subdomain rather than a standalone business domain. DNSSEC appeared to be unsigned. No malicious files, external links, or iframes were identified in the limited malware scan provided, but the strong phishing-related engine detections remain the primary technical concern at the time of this scan.
Share your experience with this website. Was it safe? Did you encounter any issues?