bafkreibvm36fn57gu5x7osnyjuuxbdkgnmtvgszm67aqaqlk55wq4n3jzq[.]ipfs[.]dweb[.]link
“Rackspace Webmail: Hosted Email for Business”
bafkreibvm36fn57gu5x7osnyjuuxbdkgnmtvgszm67aqaqlk55wq4n3jzq.ipfs.dweb.link — Inhalt nicht verfügbar. Markenidentität: Rackspace; Betrugstyp: Generic Phishing. Zusammenfassung der Beweislage: VirusTotal 20/94 (ADMINUSLabs, alphaMountain.ai, BitDefender, CRDF, CyRadar); URLQuery 3 alerts; URLScan malicious verdict; CF Radar malicious; PhishDestroy score 100/100. Registrar: CSC.
Die ausführliche Analyse von PhishDestroy AI bleibt auf Englisch, damit der ursprüngliche forensische Bericht unverändert bleibt.
This domain is flagged as an elevated-risk generic phishing threat designed to mimic corporate webmail infrastructure. Analysis indicates the resource, hosted under the InterPlanetary File System (IPFS) gateway bafkreibvm36fn57gu5x7osnyjuuxbdkgnmtvgszm67aqaqlk55wq4n3jzq.ipfs.dweb.link, specifically impersonates Rackspace Webmail login portals to harvest business email credentials. The page title, 'Rackspace Webmail: Hosted Email for Business,' aligns with known phishing tactics targeting enterprise users through spoofed authentication interfaces. Infrastructure analysis reveals the domain resolves to the IP address 209.94.90.3, geolocated within the United States under AS40680 (Protocol Labs). The domain was registered through CSC Corporate Domains, Inc. on March 9, 2026, an anomalous creation date suggesting potential domain spoofing or registry manipulation. Security telemetry indicates the domain appears on one blocklist and is actively blocked by at least one threat intelligence feed. SSL certification is provided by Let’s Encrypt (serial number E7), a common tactic among phishing actors to lend superficial legitimacy. VirusTotal detection metrics report 20 out of 95 security vendors flag the domain as malicious, a detection rate consistent with mid-tier phishing campaigns. Mitigation against this threat type requires multi-layered defensive measures. Network-level protections should include blocking the IP address 209.94.90.3 and monitoring for connections to AS40680, particularly for outbound requests to IPFS gateways. Organizations should implement strict email filtering rules to quarantine messages containing links to IPFS-hosted resources or domains registered through CSC Corporate Domains within the past 12 months. Endpoint detection systems should be configured to alert on processes attempting to access spoofed webmail domains, particularly those impersonating Rackspace infrastructure. User training should emphasize verification of SSL certificates, scrutiny of domain structures (e.g., IPFS gateways), and reporting of suspicious login pages to internal security teams for further analysis.
Erkenntnisse zur Netzwerksicherheit
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| Cloudflare DNS | bafkreibvm36fn57gu5x7osnyjuuxbdkgnmtvgszm67aqaqlk55wq4n3jzq.ipfs.dweb.link |
malicious | Sinkholed |
| DNS4EU | bafkreibvm36fn57gu5x7osnyjuuxbdkgnmtvgszm67aqaqlk55wq4n3jzq.ipfs.dweb.link |
malicious | Sinkholed |
| OpenDNS | bafkreibvm36fn57gu5x7osnyjuuxbdkgnmtvgszm67aqaqlk55wq4n3jzq.ipfs.dweb.link |
phishing | Phishing Block |
Pipeline zur Reaktion auf Sicherheitsbedrohungen
Status der öffentlichen Sperrliste
Technologien · 3 identified
Web infrastructure and security company providing CDN, DDoS mitigation, and DNS services.
www.cloudflare.comThird major version of HTTP protocol, built on QUIC for faster, more reliable connections.
VirusTotal-Analyse
Archivierte Beweise
Website-Performanceanalyse
Google PageSpeed Insights — mobile performance audit of bafkreibvm36fn57gu5x7osnyjuuxbdkgnmtvgszm67aqaqlk55wq4n3jzq.ipfs.dweb.link · checked Mar 9, 2026
Nachweise und externe Berichte
Wurden Sie von dieser Website betroffen?
Wenn Sie Kontoanmeldeinformationen, persönliche oder Zahlungsinformationen eingegeben oder eine Datei von dieser Domain heruntergeladen haben, ergreifen Sie sofort Maßnahmen. Nachfolgend finden Sie Ressourcen, die Ihnen helfen, den Vorfall zu melden und sich zu schützen.
Melden Sie sich bei Ihren örtlichen Behörden
Wählen Sie Ihr Land aus, um Offizielle Kontakte im Bereich Cyberkriminalität oder einen Beschwerdeentwurf erstellen → zu erhalten.
Jede beliebige Domain prüfen
Bedrohungsanalyse anhand gespeicherter Blocklisten, WHOIS, DNS und öffentlicher Scan-Beweise
Jetzt scannenPhishing melden
Melden Sie verdächtige Domains an unsere Bedrohungsdatenbank – schützen Sie die Community
MeldenEchtzeit-Bedrohungsfeed
Aktuelle Phishing-Meldungen und beobachtete Verfügbarkeitsänderungen
ÜberwachenBleiben Sie auf dem Laufenden, bleiben Sie sicher
Beobachten Sie aktuelle Bedrohungen oder legen Sie Widerspruch gegen diesen Eintrag ein, wenn Sie der Meinung sind, dass es sich um einen Fehlalarm handelt