bafybeigdc66io3yev7awofrteoyay6ghsx2jzqebhsim4sza26bvwm7ytq[.]ipfs[.]dweb[.]link
“CARV - Modular Data Layer for Gaming and AI”
bafybeigdc66io3yev7awofrteoyay6ghsx2jzqebhsim4sza26bvwm7ytq.ipfs.dweb.link — No verificado. Suplantación de marca: Revolut; Tipo de estafa: Impersonation. Resumen de las pruebas: VirusTotal 13/91 (alphaMountain.ai, BitDefender, ESET, Emsisoft, G-Data); 1 external blocklist match (ScamSniffer); CF Radar malicious; PhishDestroy score 94/100. Registrador: CSC.
El análisis detallado de PhishDestroy AI se mantiene en inglés para conservar el registro forense original.
This domain, bafybeigdc66io3yev7awofrteoyay6ghsx2jzqebhsim4sza26bvwm7ytq.ipfs.dweb.link, is flagged as an active high-risk brand impersonation threat targeting Revolut. Infrastructure analysis reveals the domain is hosted on IPFS and resolves to 2602:fea2:2::2, with Cloudflare nameservers (clarissa.ns.cloudflare.com, tate.ns.cloudflare.com) and a Let's Encrypt SSL certificate. The domain was created on February 24, 2017, and is registered through CSC Corporate Domains, Inc. Despite its age, it currently serves a page titled 'CARV - Modular Data Layer for Gaming and AI,' which does not align with the targeted brand, suggesting either misdirection or a compromised legitimate resource repurposed for phishing. Security vendors flag this domain, with 10 out of 95 detections on VirusTotal, and it appears on two security blocklists (PhishDestroy, ScamSniffer). The HTTP 301 redirect indicates potential redirection to another malicious endpoint, though the final destination remains unconfirmed. Technologies detected include IPFS, Google Tag Manager, Cloudflare, and HTTP/3, which may be leveraged to evade detection or track victims. Defenders should treat this domain as active and high-risk. Immediate actions include blocking resolution at the DNS level, monitoring for connections to the associated IP (2602:fea2:2::2), and investigating any internal access attempts. The discrepancy between the page title and the impersonated brand warrants further analysis to determine if this is a phishing kit, a compromised IPFS resource, or part of a broader campaign. Given the domain's age and infrastructure, retrospective log analysis may identify prior compromise activity.
Señales de seguridad
Inteligencia de seguridad de red
Proceso de respuesta ante amenazas Pipeline
Estado de la lista de bloqueados pública
Tecnologías · 4 identified
IPFS is a peer-to-peer hypermedia protocol that provides a distributed hypermedia web.
ipfs.tech 100 % de confianzaGoogle Tag Manager is a tag management system (TMS) that allows you to quickly and easily update measurement codes and related code fragments collectively known as tags on your website or mobile app.
www.google.com 100 % de confianzaCloudflare is a web-infrastructure and website-security company, providing content-delivery-network services, DDoS mitigation, Internet security, and distributed domain-name-server services.
www.cloudflare.com 100 % de confianzaHTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org 100 % de confianzaAnálisis de VirusTotal
Evidencias archivadas
Análisis de la configuración del sitio
Datos y informes externos
¿Te ha afectado esta página web?
Si ingresó credenciales de cuenta, información personal o de pago, o descargó un archivo de este dominio, tome medidas inmediatas. A continuación encontrará recursos que le ayudarán a informar el incidente y protegerse.
Informa a las autoridades locales
Seleccione su país para obtener contactos oficiales de cibercrimen o crear un borrador de queja →.
Comprobar cualquier dominio
Análisis de amenazas utilizando listas de bloqueo almacenadas, WHOIS, DNS y evidencia de escaneo público
Escanear ahoraDenunciar un intento de phishing
Envía los dominios sospechosos a nuestra base de datos de amenazas: protege a la comunidad
DenunciarFlujo de amenazas en tiempo real
Informes de phishing recientes y cambios de disponibilidad observados
MonitorizarMantente informado, mantente a salvo
Supervisa las amenazas en tiempo real o impugna esta entrada si crees que se trata de un falso positivo.