bafybeigdc66io3yev7awofrteoyay6ghsx2jzqebhsim4sza26bvwm7ytq[.]ipfs[.]dweb[.]link
“CARV - Modular Data Layer for Gaming and AI”
bafybeigdc66io3yev7awofrteoyay6ghsx2jzqebhsim4sza26bvwm7ytq.ipfs.dweb.link — Nicht bestätigt. Markenidentität: Revolut; Betrugstyp: Impersonation. Zusammenfassung der Beweislage: VirusTotal 13/91 (alphaMountain.ai, BitDefender, ESET, Emsisoft, G-Data); 1 external blocklist match (ScamSniffer); CF Radar malicious; PhishDestroy score 94/100. Registrar: CSC.
Die ausführliche Analyse von PhishDestroy AI bleibt auf Englisch, damit der ursprüngliche forensische Bericht unverändert bleibt.
This domain, bafybeigdc66io3yev7awofrteoyay6ghsx2jzqebhsim4sza26bvwm7ytq.ipfs.dweb.link, is flagged as an active high-risk brand impersonation threat targeting Revolut. Infrastructure analysis reveals the domain is hosted on IPFS and resolves to 2602:fea2:2::2, with Cloudflare nameservers (clarissa.ns.cloudflare.com, tate.ns.cloudflare.com) and a Let's Encrypt SSL certificate. The domain was created on February 24, 2017, and is registered through CSC Corporate Domains, Inc. Despite its age, it currently serves a page titled 'CARV - Modular Data Layer for Gaming and AI,' which does not align with the targeted brand, suggesting either misdirection or a compromised legitimate resource repurposed for phishing. Security vendors flag this domain, with 10 out of 95 detections on VirusTotal, and it appears on two security blocklists (PhishDestroy, ScamSniffer). The HTTP 301 redirect indicates potential redirection to another malicious endpoint, though the final destination remains unconfirmed. Technologies detected include IPFS, Google Tag Manager, Cloudflare, and HTTP/3, which may be leveraged to evade detection or track victims. Defenders should treat this domain as active and high-risk. Immediate actions include blocking resolution at the DNS level, monitoring for connections to the associated IP (2602:fea2:2::2), and investigating any internal access attempts. The discrepancy between the page title and the impersonated brand warrants further analysis to determine if this is a phishing kit, a compromised IPFS resource, or part of a broader campaign. Given the domain's age and infrastructure, retrospective log analysis may identify prior compromise activity.
Sicherheitssignale
Erkenntnisse zur Netzwerksicherheit
Pipeline zur Reaktion auf Sicherheitsbedrohungen
Status der öffentlichen Sperrliste
Technologien · 4 identified
IPFS is a peer-to-peer hypermedia protocol that provides a distributed hypermedia web.
ipfs.tech 100 % KonfidenzGoogle Tag Manager is a tag management system (TMS) that allows you to quickly and easily update measurement codes and related code fragments collectively known as tags on your website or mobile app.
www.google.com 100 % KonfidenzCloudflare is a web-infrastructure and website-security company, providing content-delivery-network services, DDoS mitigation, Internet security, and distributed domain-name-server services.
www.cloudflare.com 100 % KonfidenzHTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org 100 % KonfidenzVirusTotal-Analyse
Archivierte Beweise
Analyse der Website-Konfiguration
Nachweise und externe Berichte
Wurden Sie von dieser Website betroffen?
Wenn Sie Kontoanmeldeinformationen, persönliche oder Zahlungsinformationen eingegeben oder eine Datei von dieser Domain heruntergeladen haben, ergreifen Sie sofort Maßnahmen. Nachfolgend finden Sie Ressourcen, die Ihnen helfen, den Vorfall zu melden und sich zu schützen.
Melden Sie sich bei Ihren örtlichen Behörden
Wählen Sie Ihr Land aus, um Offizielle Kontakte im Bereich Cyberkriminalität oder einen Beschwerdeentwurf erstellen → zu erhalten.
Jede beliebige Domain prüfen
Bedrohungsanalyse anhand gespeicherter Blocklisten, WHOIS, DNS und öffentlicher Scan-Beweise
Jetzt scannenPhishing melden
Melden Sie verdächtige Domains an unsere Bedrohungsdatenbank – schützen Sie die Community
MeldenEchtzeit-Bedrohungsfeed
Aktuelle Phishing-Meldungen und beobachtete Verfügbarkeitsänderungen
ÜberwachenBleiben Sie auf dem Laufenden, bleiben Sie sicher
Beobachten Sie aktuelle Bedrohungen oder legen Sie Widerspruch gegen diesen Eintrag ein, wenn Sie der Meinung sind, dass es sich um einen Fehlalarm handelt