bafybeieo4yatzqc2xgn26pfjyxk6qhmvevorblcwqvk5pmivmmy254rxj4[.]ipfs[.]infura-ipfs[.]io
“Webmail”
bafybeieo4yatzqc2xgn26pfjyxk6qhmvevorblcwqvk5pmivmmy254rxj4.ipfs.infura-ipfs.io — المحتوى غير متوفر. انتحال العلامة التجارية: Genericemail. ملخص الأدلة: VirusTotal 18/95 (BitDefender, CRDF, CyRadar, ESET, Emsisoft); URLScan malicious verdict; CF Radar malicious; PhishDestroy score 100/100. مسجّل النطاق: GANDI SAS.
يبقى تحليل PhishDestroy AI المفصل أدناه باللغة الإنجليزية للحفاظ على السجل الجنائي الرقمي الأصلي.
This domain, bafybeieo4yatzqc2xgn26pfjyxk6qhmvevorblcwqvk5pmivmmy254rxj4.ipfs.infura-ipfs.io, poses an elevated-risk generic phishing threat specifically targeting webmail credentials. Analysis of the page title, "Webmail," indicates an attempt to mimic legitimate email login portals, tricking users into submitting sensitive authentication details. Such infrastructure is commonly used in credential harvesting campaigns, where stolen login data is later exploited for unauthorized access, data exfiltration, or further phishing attacks against contacts. Evidence supporting this assessment includes detection by 18 out of 95 security vendors on VirusTotal, registration through GANDI SAS since January 30, 2020, and presence on two security blocklists. The domain resolves to the IP address 209.94.90.3, hosted under AS40680 (Protocol Labs) in the United States. The SSL certificate, issued by Amazon RSA 2048 M02, does not mitigate the malicious intent, as phishing domains frequently leverage valid certificates to appear legitimate. The domain’s inclusion in PhishDestroy and PhishingDB further corroborates its classification as malicious infrastructure. Users who visited this domain or entered credentials should immediately reset passwords for any accounts accessed from the same device or network. Enable multi-factor authentication (MFA) on all critical accounts to prevent unauthorized access. Monitor financial and communication platforms for unusual activity, as stolen credentials may be used in follow-up attacks. If corporate credentials were exposed, report the incident to internal security teams for containment and forensic analysis. Avoid interacting with any links or attachments from suspicious emails, and verify the legitimacy of webmail portals by checking domain names and SSL certificate details before entering credentials.
مؤشرات الأمان
استخبارات أمن الشبكات
مسار الاستجابة للتهديدات Pipeline
حالة قوائم الحظر العامة
التقنيات · 2 identified
Amazon Web Services (AWS) is a comprehensive cloud services platform offering compute power, database storage, content delivery and other functionality.
aws.amazon.com ثقة 100٪AWS Certificate Manager is a service that lets you easily provision, manage, and deploy public and private Secure Sockets Layer/Transport Layer Security (SSL/TLS) certificates for use with AWS services and your internal connected resources.
aws.amazon.com ثقة 100٪تحليل VirusTotal
الأدلة والتقارير الخارجية
هل تأثرت بهذا الموقع؟
إذا أدخلت بيانات اعتماد الحساب أو المعلومات الشخصية أو معلومات الدفع أو قمت بتنزيل ملف من هذا النطاق، فاتخذ إجراءً فوريًا. فيما يلي موارد لمساعدتك في الإبلاغ عن الحادث وحماية نفسك.
أبلغ السلطات المحلية
حدد بلدك للحصول على الاتصالات الرسمية المتعلقة بالجرائم الإلكترونية أو إنشاء مسودة شكوى →.
تحقق من أي نطاق
تحليل التهديدات باستخدام قائمة الحظر المخزنة، وWHOIS، وDNS، وأدلة الفحص العامة
امسح الآنالإبلاغ عن محاولة تصيد احتيالي
أرسل النطاقات المشبوهة إلى قاعدة بيانات التهديدات الخاصة بنا — ساهم في حماية المجتمع
إبلاغتحديثات فورية حول التهديدات
تقارير التصيد الاحتيالي الأخيرة وتغييرات التوفر الملحوظة
مراقبةابقَ على اطلاع، وابقَ آمنًا
راقب التهديدات في الوقت الفعلي أو اعترض على هذا الإدراج إذا كنت تعتقد أنه إنذار كاذب