ldrsimnxcg9.rodric05.workers[.]dev
Category: Phishing
To use full-featured product, you have to purchase a license for Combo Cleaner. Limited seven days free trial available. Combo Cleaner is owned and operated by RCS LT, the parent company of PCRisk.com.
Description of ldrsimnxcg9.rodric05.workers[.]dev
This domain appears to be a subdomain hosted on the workers.dev platform, which is commonly used to deploy serverless web applications and edge-hosted content. The randomized-looking subdomain label does not clearly indicate a brand, organization, or public-facing service, so its intended purpose is not obvious from the name alone. Based on the available data, it may be a temporary or programmatically generated endpoint rather than a conventional business website.
The infrastructure points to a Cloudflare-hosted environment, and the observed links reference Cloudflare error-handling and challenge resources. That suggests the page may be using edge delivery, access controls, or anti-bot protections. However, there is no clear evidence in the provided scan data of a legitimate organization identity, product offering, or informational content associated with this specific subdomain.
Safety Assessment for ldrsimnxcg9.rodric05.workers[.]dev
The strongest signal in this scan is that the URL was flagged by 14 out of 92 security engines, with multiple engines classifying it as phishing at the time of this scan. That level of multi-engine agreement is a meaningful risk indicator, especially for a little-known, unranked subdomain with no clear public identity. Although blacklist databases included here were largely clean, blacklist coverage can lag behind newly created or short-lived abusive pages, and a clean result there does not outweigh broad phishing detections from multiple security engines.
The malware scan did not identify malicious files, and no suspicious external links or iframes were reported in the limited page resources that were scanned. That may indicate the page is lightweight, blocked behind an interstitial, or designed primarily for credential harvesting rather than malware delivery. The domain itself is older, but because this is a hosted subdomain on a shared platform, the age of the parent registration does not necessarily establish trust for this specific endpoint.
Based on these findings, this website may pose potential risks to visitors. In particular, the concentration of phishing-related detections suggests caution is warranted at the time of this scan.
Technical Description
The site is served through Cloudflare infrastructure and presents a valid TLS certificate issued by Google Trust Services, with expiry in July 2026. Hosting resolves to a Cloudflare IP in Toronto, Canada, and the web server is identified as Cloudflare. DNSSEC appears to be unsigned based on the provided records.
From a technical standpoint, the use of a reputable CDN and valid HTTPS only indicates that transport encryption is in place; it does not by itself validate the trustworthiness of the content behind the subdomain. The workers.dev hosting model can be used for legitimate applications, but it may also be used for disposable or rapidly rotated pages, which can complicate attribution and increase uncertainty when a subdomain has no established reputation.
Share your experience with this website. Was it safe? Did you encounter any issues?