yqgqt-mnec-vbcz.c-0zsklfju.workers[.]dev
Category: Phishing
To use full-featured product, you have to purchase a license for Combo Cleaner. Limited seven days free trial available. Combo Cleaner is owned and operated by RCS LT, the parent company of PCRisk.com.
Description of yqgqt-mnec-vbcz.c-0zsklfju.workers[.]dev
This domain appears to be a Cloudflare Workers subdomain rather than a conventional branded website. The hostname is a long, random-looking string under workers.dev, which is commonly used to deploy lightweight web applications, redirects, temporary pages, or serverless content. Based on the screenshot, the page presents a minimal loading screen with the message "Preparing your secure document..." and does not provide clear branding, ownership details, or an explanation of the service.
Because the visible content is sparse and the hostname does not indicate a recognizable organization, the site may be intended for single-purpose delivery such as document sharing, gated access, or redirection. The underlying workers.dev platform is legitimate infrastructure, but individual subdomains on shared platforms can be created and repurposed by different operators, so the specific operator of this page is not evident from the available data.
Safety Assessment for yqgqt-mnec-vbcz.c-0zsklfju.workers[.]dev
The strongest signal in this scan is that 15 out of 92 security engines flagged the URL, with most of those detections describing phishing or malicious behavior. That level of multi-engine agreement is a meaningful risk indicator, even though some blacklist and malware-scan sources did not report a threat at the time of this scan. The page itself also shows a vague "secure document" loading message without visible branding or context, which can be consistent with lures used to prompt user interaction or credential entry.
At the same time, not every data source agreed: the malware scan reported no flagged files, and several blacklist databases were clean at the time of this scan. The domain age is also older than many throwaway phishing pages, although this is a shared subdomain environment where age may reflect the parent platform more than the specific content instance. In this context, the combination of a random-looking subdomain, minimal page content, and substantial multi-engine phishing detections outweighs the cleaner signals.
Based on these findings, this website may pose potential risks to visitors.
Technical Description
The site is served over HTTPS with a valid Let's Encrypt certificate, and the server infrastructure appears to be hosted behind Cloudflare in Toronto, Canada. The web server is identified as Cloudflare, and the domain uses Cloudflare nameservers. DNSSEC appears to be unsigned, which is not uncommon but means DNS responses do not benefit from DNSSEC validation.
From a technical perspective, the use of a reputable CDN and a valid TLS certificate does not by itself establish trustworthiness, since both are commonly used by legitimate and abusive sites alike. The main technical concern here is the use of a random-looking workers.dev subdomain on shared serverless infrastructure, which can make attribution difficult and may be used for rapidly deployed phishing pages.
Share your experience with this website. Was it safe? Did you encounter any issues?