bafkreibvm36fn57gu5x7osnyjuuxbdkgnmtvgszm67aqaqlk55wq4n3jzq[.]ipfs[.]dweb[.]link
“Rackspace Webmail: Hosted Email for Business”
bafkreibvm36fn57gu5x7osnyjuuxbdkgnmtvgszm67aqaqlk55wq4n3jzq.ipfs.dweb.link — Contenu indisponible. Usurpation de l'identité de la marque : Rackspace; Type d'arnaque : Generic Phishing. Résumé des preuves: VirusTotal 20/94 (ADMINUSLabs, alphaMountain.ai, BitDefender, CRDF, CyRadar); URLQuery 3 alerts; URLScan malicious verdict; CF Radar malicious; PhishDestroy score 100/100. Bureau d’enregistrement: CSC.
L’analyse détaillée de PhishDestroy AI reste en anglais afin de préserver le relevé forensique original.
This domain is flagged as an elevated-risk generic phishing threat designed to mimic corporate webmail infrastructure. Analysis indicates the resource, hosted under the InterPlanetary File System (IPFS) gateway bafkreibvm36fn57gu5x7osnyjuuxbdkgnmtvgszm67aqaqlk55wq4n3jzq.ipfs.dweb.link, specifically impersonates Rackspace Webmail login portals to harvest business email credentials. The page title, 'Rackspace Webmail: Hosted Email for Business,' aligns with known phishing tactics targeting enterprise users through spoofed authentication interfaces. Infrastructure analysis reveals the domain resolves to the IP address 209.94.90.3, geolocated within the United States under AS40680 (Protocol Labs). The domain was registered through CSC Corporate Domains, Inc. on March 9, 2026, an anomalous creation date suggesting potential domain spoofing or registry manipulation. Security telemetry indicates the domain appears on one blocklist and is actively blocked by at least one threat intelligence feed. SSL certification is provided by Let’s Encrypt (serial number E7), a common tactic among phishing actors to lend superficial legitimacy. VirusTotal detection metrics report 20 out of 95 security vendors flag the domain as malicious, a detection rate consistent with mid-tier phishing campaigns. Mitigation against this threat type requires multi-layered defensive measures. Network-level protections should include blocking the IP address 209.94.90.3 and monitoring for connections to AS40680, particularly for outbound requests to IPFS gateways. Organizations should implement strict email filtering rules to quarantine messages containing links to IPFS-hosted resources or domains registered through CSC Corporate Domains within the past 12 months. Endpoint detection systems should be configured to alert on processes attempting to access spoofed webmail domains, particularly those impersonating Rackspace infrastructure. User training should emphasize verification of SSL certificates, scrutiny of domain structures (e.g., IPFS gateways), and reporting of suspicious login pages to internal security teams for further analysis.
Renseignements sur la sécurité réseau
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| Cloudflare DNS | bafkreibvm36fn57gu5x7osnyjuuxbdkgnmtvgszm67aqaqlk55wq4n3jzq.ipfs.dweb.link |
malicious | Sinkholed |
| DNS4EU | bafkreibvm36fn57gu5x7osnyjuuxbdkgnmtvgszm67aqaqlk55wq4n3jzq.ipfs.dweb.link |
malicious | Sinkholed |
| OpenDNS | bafkreibvm36fn57gu5x7osnyjuuxbdkgnmtvgszm67aqaqlk55wq4n3jzq.ipfs.dweb.link |
phishing | Phishing Block |
Processus de réponse aux menaces Pipeline
Statut de la liste de blocage publique
Technologies · 3 identified
Web infrastructure and security company providing CDN, DDoS mitigation, and DNS services.
www.cloudflare.comThird major version of HTTP protocol, built on QUIC for faster, more reliable connections.
Analyse VirusTotal
Preuves archivées
Analyse des performances du site
Google PageSpeed Insights — mobile performance audit of bafkreibvm36fn57gu5x7osnyjuuxbdkgnmtvgszm67aqaqlk55wq4n3jzq.ipfs.dweb.link · checked Mar 9, 2026
Données factuelles et rapports externes
Ce site vous a-t-il affecté ?
Si vous avez saisi des informations d'identification de compte, des informations personnelles ou de paiement, ou téléchargé un fichier à partir de ce domaine, agissez immédiatement. Vous trouverez ci-dessous des ressources pour vous aider à signaler l'incident et à vous protéger.
Signalez-le à vos autorités locales
Sélectionnez votre pays pour obtenir contacts officiels en matière de cybercriminalité ou créer un projet de plainte →.
Vérifier n'importe quel domaine
Analyse des menaces à l'aide de listes de blocage stockées, de WHOIS, de DNS et de preuves d'analyse publique
Scanner maintenantSignaler une tentative d'hameçonnage
Signalez les domaines suspects à notre base de données des menaces — protégez la communauté
SignalerFlux d'alertes en temps réel
Rapports de phishing récents et changements de disponibilité observés
SurveillerRestez informés, restez en sécurité
Surveillez les menaces en temps réel ou signalez cette alerte si vous pensez qu'il s'agit d'un faux positif