ldrmrdftr.esaic4.workers.dev
Category: Phishing
To use full-featured product, you have to purchase a license for Combo Cleaner. Limited seven days free trial available. Combo Cleaner is owned and operated by RCS LT, the parent company of PCRisk.com.
Description of ldrmrdftr.esaic4.workers.dev
The domain ldrmrdftr.esaic4.workers.dev appears to be a subdomain hosted on the Cloudflare Workers platform, which is commonly used to deploy serverless web applications, redirects, APIs, and lightweight web pages. The hostname structure suggests this is not a conventional branded website but rather a custom worker endpoint operating under a shared workers.dev environment.
Based on the available scan context, the page does not appear to present a typical business, media, or consumer service website. The observed resources reference Cloudflare error-page styling and challenge infrastructure, which may indicate the endpoint was returning an access-control, challenge, or error state at the time of inspection rather than a fully rendered public-facing site.
Because this is a workers.dev subdomain rather than a standalone branded domain, attribution to a specific organization is not clear from the hostname alone. The underlying infrastructure appears to be operated through Cloudflare's hosting and edge network, but that does not by itself identify the party controlling the specific worker content.
Safety Assessment for ldrmrdftr.esaic4.workers.dev
This domain was flagged by 16 out of 91 security engines at the time of the scan, with multiple detections describing the page as phishing or otherwise malicious. That level of multi-engine agreement is a meaningful risk signal, especially for a little-known subdomain with no ranking presence and no clear public brand identity. Although blacklist checks included in the scan were limited and some databases reported no listing, the concentration of phishing-related detections materially raises concern.
The malware scan included with the report did not identify malicious files, and the observed external links were limited to Cloudflare-related resources. However, a clean file scan does not rule out credential-harvesting, deceptive redirects, or short-lived phishing content, particularly on serverless hosting platforms where page behavior can change quickly and where phishing pages may contain minimal static malware artifacts.
The published trust score for this scan is very low, and that aligns with the broader phishing-related detection pattern. Based on these findings, this website may pose potential risks to visitors.
Technical Description
The site is hosted on Cloudflare infrastructure and resolves to an IP address associated with Cloudflare's edge network in Toronto, Canada. It presents a valid TLS certificate issued by Google Trust Services, with expiry in July 2026. The web server is identified as Cloudflare, and the domain uses Cloudflare nameservers. DNSSEC appears to be unsigned at the time of this scan.
From a technical standpoint, the visible resources suggest the endpoint may have been serving Cloudflare challenge or error-related assets during inspection rather than a normal application page. While the TLS setup appears valid, certificate validity and major-edge hosting are not, by themselves, indicators of legitimacy; such infrastructure is also commonly used by temporary or rapidly changing pages.
Share your experience with this website. Was it safe? Did you encounter any issues?