Skip to security report
Domain security and threat intelligence
bafkreidwdybc7dlcr3vbbuqme4joydimyoryfqv3lc7cci3xmxbcmwt2qm.ipfs.dweb.link favicon

bafkreidwdybc7dlcr3vbbuqme4joydimyoryfqv3lc7cci3xmxbcmwt2qm.ipfs.dweb.link

“EmailLogin”

Threat verdict Critical 100/100 evidence score
Availability Last known active Latest stored reachability observation
VirusTotal detections: 14/89 Scam type: Credential Phishing Last known active
Jun 15, 2026 CDN
Actions API
⚠️
This domain has been flagged as malicious
Security engines reporting a detection: 14. Exercise extreme caution — do not enter credentials or personal information.

Evidence Summary

CRITICAL
Score
100/100

This domain, bafkreidwdybc7dlcr3vbbuqme4joydimyoryfqv3lc7cci3xmxbcmwt2qm.ipfs.dweb.link, is flagged as a high-risk credential phishing threat. Analysis indicates the site presents an 'EmailLogin' page title, suggesting an attempt to harvest user credentials. The domain remains active as of July 12, 2026, and is currently listed on one security blocklist. Infrastructure analysis reveals it resolves to IP 209.94.90.2, hosted by Protocol Labs in the US, and uses Cloudflare nameservers (clarissa.ns.cloudflare.com, tate.ns.cloudflare.com). The domain was registered on May 11, 2026, through CSC Corporate Domains, Inc., and employs a Let's Encrypt SSL certificate (E8). The HTTP status returns 200, confirming the site is accessible. Eighteen of ninety-one security vendors on VirusTotal have detected this domain as malicious. Defenders should treat this domain as an active phishing threat, block resolution at the DNS level, and monitor for credential submission attempts originating from this infrastructure. The exact content and targeted brand are not yet confirmed, but the page title and scam classification indicate a focus on credential theft.

VirusTotal
VirusTotal
14 det.
TLS Certificate
Expired or unverified -84d
Age
4 mo
Observed status
Last known active 301
PhishDestroy
DestroyList
Listed
Data coverage VirusTotal 14 / 89 URLQuery source data unavailable PhishStats not checked OTX no community references CF Radar no data URLScan capture not submitted URLScan verdict verdict unavailable DNS blocks not checked TLS Expired or unverified WHOIS 4 mo old Screenshot stored capture Redirect chain not probed

Threat Response Pipeline

Discovery
Checks
Reports
Availability
6/8

Public Blocklist Status

Evidence Capture

Live Snapshot
2026-06-15 00:27 UTC
Malicious · 14/89 engines
Forensic screenshot of bafkreidwdybc7dlcr3vbbuqme4joydimyoryfqv3lc7cci3xmxbcmwt2qm.ipfs.dweb.link showing the phishing page layout
IP: 209.94.90.2
CSC Corporate Domains, Inc.
126d old
Page Title
EmailLogin

Public Blocklist Status

Stored observation

Observed title contrast

Scanner-facing title301 Moved Permanently
Visitor-facing titleEmailLogin

Stored Capture · 1 source

Domain Intelligence

Domain
Server / ASN cloudflare · AS40680 Protocol Labs
IP Context Cloudflare shared edge origin IP hidden Edge-IP reputation is not attributed to this domain.
Platform provider CSC US(US)
IP Address 209.94.90.2 CDN
GeoUS San Francisco, US
NetworkAS40680 · Protocol Labs
The origin IP is hidden behind a CDN proxy. Reverse-IP results for the edge address contain unrelated tenants; finding the origin requires passive DNS or certificate-transparency data.
HTTP Status301 Moved Permanently
Technical detailsDNS, SSL SANs, timestamps
First DetectedJun 15, 2026
Nameserverstate.ns.cloudflare.com
TLS Fingerprint
TLS Observationvalid from Mar 25, 2026scanned May 11, 2026
TLS SAN Domainsdweb.link
Favicon Hash
Page Title
EmailLogin
TLS Certificate
Expired or unverified · Issued by Let's Encrypt / E8
Report This Domain Submit evidence & help protect others

VirusTotal Analysis

14 / 89 security vendors flagged this domain
View on VT
Last analyzed Previous stored snapshot: 17 detections
alphaMountain.ai
BitDefender
ESET
Emsisoft
Forcepoint ThreatSeeker
Fortinet
G-Data
Gridinsoft
Kaspersky
Lionic
Netcraft
Sophos
VIPRE
Webroot

Community reports

Reported by 1 community member, first seen May 11, 2026

Stored reports
1
Unique reported URLs
1
Accepted1

Evidence & External Reports

Were You Affected by This Site?

If credentials were compromised, report immediately. Do not engage with recovery scammers.

If credentials, payment data, or files were exposed, report the incident immediately. Change affected passwords, revoke active sessions, and scan the device.

Europol
Find the official reporting channel for your EU country
National police directory
Beware of recovery scammers! Recovery scammers may pose as investigators, lawyers, or tracing services. Do not pay upfront fees or disclose credentials. Learn more about recovery fraud →

Report to Your Local Authorities

Select your country to get official cybercrime contacts, or create a complaint draft →.

97-country directory
Template-based draft • optional AI wording assistance requires separate consent Review and submit it yourself

Stay Informed, Stay Safe

Monitor live threats or contest this listing if you believe it's a false positive

Live Threat Feed Appeal This Listing
HTML · IFRAME

Embed This Report

Share this threat intelligence on your website or blog

embed.html
<iframe
  src="https://phishdestroy.io/embed/domain/bafkreidwdybc7dlcr3vbbuqme4joydimyoryfqv3lc7cci3xmxbcmwt2qm.ipfs.dweb.link"
  title="PhishDestroy threat report for bafkreidwdybc7dlcr3vbbuqme4joydimyoryfqv3lc7cci3xmxbcmwt2qm.ipfs.dweb.link"
  width="100%" height="320"
  loading="lazy"
  referrerpolicy="no-referrer"
  sandbox="allow-same-origin allow-popups allow-popups-to-escape-sandbox"
  style="border:0;border-radius:12px;max-width:100%"
></iframe>