bafkreicyghdtqspqrperjhwyfum7blmddcsnbeegsm5n46dfjkgypjcste[.]ipfs[.]dweb[.]link
“EmailLogin”
bafkreicyghdtqspqrperjhwyfum7blmddcsnbeegsm5n46dfjkgypjcste.ipfs.dweb.link — No verificado. Tipo de estafa: Credential Phishing. Resumen de las pruebas: VirusTotal 19/91 (ADMINUSLabs, alphaMountain.ai, BitDefender, Chong Lua Dao, CRDF); URLQuery 5 alerts; PhishDestroy score 95/100. Registrador: CSC.
El análisis detallado de PhishDestroy AI se mantiene en inglés para conservar el registro forense original.
The domain bafkreicyghdtqspqrperjhwyfum7blmddcsnbeegsm5n46dfjkgypjcste.ipfs.dweb.link resolves to IP 209.94.90.2, an address registered to a US entity associated with Protocol Labs. The site presents a page titled "EmailLogin" and serves content over HTTPS using a Let’s Encrypt certificate (E8). Registration data shows the domain was created on February 24 2017 through CSC Corporate Domains, Inc. Security telemetry indicates the domain is currently active and has been flagged by 20 of 91 vendors on VirusTotal, while Gridinsoft assigns a trust score of 0 / 100. It is listed on one public blocklist and has been blocked by the PhishDestroy filtering service. The observed characteristics align with a credential‑phishing campaign targeting email credentials. Uncertainty remains around the specific phishing kit or any downstream infrastructure, as no additional indicators such as payload hashes or related command‑and‑control hosts have been disclosed. Defenders should prioritize blocking the domain and its resolved IP at perimeter and endpoint layers, enforce strict URL filtering for the ipfs.dweb.link suffix, and monitor TLS certificate changes for the Let’s Encrypt issuance. Continuous threat‑intel feeds should be consulted for any new detections linked to this IP or associated registrant, and incident response teams should be prepared to investigate credential‑theft attempts that reference the "EmailLogin" page title.
Inteligencia de seguridad de red
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| OpenDNS | bafkreicyghdtqspqrperjhwyfum7blmddcsnbeegsm5n46dfjkgypjcste.ipfs.inbrowser.link |
phishing | Phishing Block |
| DNS4EU | bafkreicyghdtqspqrperjhwyfum7blmddcsnbeegsm5n46dfjkgypjcste.ipfs.inbrowser.link |
malicious | Sinkholed |
| Cloudflare DNS | bafkreicyghdtqspqrperjhwyfum7blmddcsnbeegsm5n46dfjkgypjcste.ipfs.dweb.link |
malicious | Sinkholed |
| OpenDNS | bafkreicyghdtqspqrperjhwyfum7blmddcsnbeegsm5n46dfjkgypjcste.ipfs.dweb.link |
phishing | Phishing Block |
| DNS4EU | bafkreicyghdtqspqrperjhwyfum7blmddcsnbeegsm5n46dfjkgypjcste.ipfs.dweb.link |
malicious | Sinkholed |
Proceso de respuesta ante amenazas Pipeline
Estado de la lista de bloqueados pública
Captura guardada
Inteligencia de dominios
Detalles técnicosDNS, SAN de SSL, marcas de tiempo
Análisis de VirusTotal
Datos y informes externos
¿Te ha afectado esta página web?
Si ingresó credenciales de cuenta, información personal o de pago, o descargó un archivo de este dominio, tome medidas inmediatas. A continuación encontrará recursos que le ayudarán a informar el incidente y protegerse.
Informa a las autoridades locales
Seleccione su país para obtener contactos oficiales de cibercrimen o crear un borrador de queja →.
Comprobar cualquier dominio
Análisis de amenazas utilizando listas de bloqueo almacenadas, WHOIS, DNS y evidencia de escaneo público
Escanear ahoraDenunciar un intento de phishing
Envía los dominios sospechosos a nuestra base de datos de amenazas: protege a la comunidad
DenunciarFlujo de amenazas en tiempo real
Informes de phishing recientes y cambios de disponibilidad observados
MonitorizarMantente informado, mantente a salvo
Supervisa las amenazas en tiempo real o impugna esta entrada si crees que se trata de un falso positivo.