Phishing detection: dh2.googlesafebrowsingapi.workers.dev

Google
https://dh2.googlesafebrowsingapi.workers.dev Access site
Screenshot
Screenshot of dh2.googlesafebrowsingapi.workers.dev
Investigate
Domain dh2.googlesafebrowsingapi.workers.dev3 CT hosts on apex
URL https://dh2.googlesafebrowsingapi.workers.dev
Cert Google Trust Services
Phishunt analysis Beta
25 low suspicionheuristic risk score · not a probability
Why?
  • +5.3 Keyword match
  • +5.1 Site cluster
  • +5.1 urlscan.io
  • +3.7 Brand in domain label
  • +1.1 ASN reputation
  • +1.1 No CSP header
  • +0.7 Brand in cert SAN
  • +0.6 Long domain
  • +0.6 Final host mismatch
  • +0.6 Suspicious TLD
  • +0.5 Young certificate
  • +0.3 Free CA
  • +0.3 Deep subdomain
18 signals fired · detector v3.0.0
AI analysis AIBeta
Credential harvesting

Impersonates Google by spoofing the Google Safe Browsing API on a Cloudflare Workers free-tier host. The brand appears in the domain apex and the certificate SAN. Flagged malicious by urlscan, the site is likely designed to deceive users into trusting it before harvesting credentials.

urlscan.ioBrand in domain labelPaaS host
AI-generated from stored detector signals - the AI never visited the site. · 2026-08-27 · confidence 70%
Domain & Network
Whois
Registrar CloudFlare, Inc.
Network
Country United StatesUnited States
ASN AS13335
External detection urlscan.io
CleanGoogle Safe Browsing · OpenPhish · PhishTank · TweetFeed
Report this phishing
PaaS platform Cloudflare Workers
Registrar CloudFlare, Inc.

Tracked from 2026-08-26 05:54 UTC  ·  Last refreshed 2026-08-31 09:30 UTC