Scan report · about 1 month agoPublic

file-iwl3.w-4mm9yl.workers.dev

172.67.180.236AS13335 · US
Engine tags
ClickFix
Verdict

What happened

Step by step, from what the scanner recorded.
Load 14.8 s · 3 requests
01 · Visitor opensfile-iwl3.w-4mm9yl.workers.dev
02 · Page shown
...
03 · OutcomeThe visitor runs the payload themselvesPaste, Enter — no download and no login form for a filter to catch.

Be careful — warning signs found

Automated

This site shows signs commonly seen in scams or impersonation, but we could not confirm it for certain. It may be a real threat, or it may be a legitimate site that simply looks unusual to our automated checks.

What to do

Avoid entering passwords or payment details until you are sure it is genuine. Open the company directly from its known website or app instead of this link. Check the evidence below and escalate to your analyst if unsure.

"Suspicious" is a caution, not a confirmation — it can be a false alarm. The evidence below explains why it was flagged.

Findings

Strongest first
Suspicious fileSuspicious content in the downloaded file
675a3f41-ce45-453c-8528-584c09942294.html

Our Content Inspection engine downloaded the file this URL serves and analyzed it. The payload shows traits commonly seen in malware. Treat it as unsafe until verified.

Success

SHA-256 16d00811225660e5511b74d5dd39fab160ed8eb39b1dfc4e350ea189301f6919

Infrastructure

IP
172.67.180.236CLOUDFLARENET - Cloudflare, Inc., US · AS13335US
TLS
CN=YE2, O=Let's Encrypt, C=US · expires Oct 23, 2026
39 malicious8 suspicious

Hashes & fingerprints

Page capture

Live

Title “...”

Engines

8 · time to verdict

Page

HTTP
200 · Completed
Title
...
Load
14.84 s · 3 requests
Stack · 3CloudflareHSTSHTTP/3