Phishing detection: yongge9.chatgpt841105.workers.dev

ChatGPT
https://yongge9.chatgpt841105.workers.dev Access site
Screenshot
Screenshot of yongge9.chatgpt841105.workers.dev
Investigate
Domain yongge9.chatgpt841105.workers.dev14 CT hosts on apex
URL https://yongge9.chatgpt841105.workers.dev
Cert Google Trust Services
Phishunt analysis Beta
28 low suspicionheuristic risk score · not a probability
Why?
  • +5.3 Keyword match
  • +5.1 Site cluster
  • +5.1 urlscan.io
  • +3.7 Brand in domain label
  • +3.4 Shared IP cluster
  • +1.1 ASN reputation
  • +1.1 No CSP header
  • +0.9 Young certificate
  • +0.7 Brand in cert SAN
  • +0.6 Long domain
  • +0.6 Suspicious TLD
  • +0.3 Free CA
  • +0.3 Deep subdomain
  • +0.1 External scripts
17 signals fired · detector v3.0.0
AI analysis AIBeta
Credential harvesting

Site impersonates ChatGPT via a Cloudflare Workers subdomain embedding the brand name in the apex label and TLS certificate. It redirects visitors to a different final host and has been flagged by urlscan as malicious, consistent with credential harvesting targeting ChatGPT users.

Brand in domain labelBrand in cert SANPaaS host
AI-generated from stored detector signals - the AI never visited the site. · 2026-08-23 · confidence 65%
Domain & Network
Whois
Registrar CloudFlare, Inc.
Network
Country United StatesUnited States
ASN AS13335
External detection urlscan.io
CleanGoogle Safe Browsing · OpenPhish · PhishTank · TweetFeed
Report this phishing
PaaS platform Cloudflare Workers
Registrar CloudFlare, Inc.

Tracked from 2026-08-22 20:37 UTC  ·  Last refreshed 2026-08-23 21:30 UTC