bafybeielizhnh2kfpdv2iivhqh4ttf4kqfecv2qyislghqacr6n5gzcfzm[.]ipfs[.]dweb[.]link
“Vana - The First Network for User-Owned Data and Decentralized AI”
bafybeielizhnh2kfpdv2iivhqh4ttf4kqfecv2qyislghqacr6n5gzcfzm.ipfs.dweb.link — Contenu indisponible. Résumé des preuves: VirusTotal 1/95 (alphaMountain.ai); 1 external blocklist match (ScamSniffer); PhishDestroy score 63/100. Bureau d’enregistrement: CSC.
L’analyse détaillée de PhishDestroy AI reste en anglais afin de préserver le relevé forensique original.
The domain bafybeielizhnh2kfpdv2iivhqh4ttf4kqfecv2qyislghqacr6n5gzcfzm.ipfs.dweb.link is currently offline, returning an HTTP 410 Gone response. Infrastructure analysis shows it resolves to IP address 209.94.90.2, which is assigned to AS40680 (Protocol Labs) and geolocated in the United States. The domain is served through Cloudflare, using Cloudflare’s nameservers (clarissa.ns.cloudflare.com and tate.ns.cloudflare.com) and supports HTTP/3. TLS is provided by a Let’s Encrypt certificate (issuer E7), indicating a valid HTTPS endpoint despite the site’s offline status.
Registration data reveals the domain was created on 24 February 2017 via CSC Corporate Domains, Inc., but no recent renewal information is available. The page title retrieved from the last known snapshot is "Vana - The First Network for User-Owned Data and Decentralized AI," which does not correspond to any known legitimate brand and appears unrelated to the observed threat vector. Reputation signals are poor: Scamadviser assigns a trust score of 10 out of 100, and the domain appears on two security blocklists (PhishDestroy and ScamSniffer). VirusTotal analysis shows that one of ninety‑five scanning engines flagged the domain, providing additional confirmation of malicious intent.
The primary uncertainty is the actual content and phishing payload, as the site is no longer serving pages, preventing a detailed content‑level assessment. Defenders should block both the domain and its resolved IP address at perimeter and DNS layers, monitor for any re‑registration or resurrection of the host, and incorporate the observed indicators (Cloudflare nameservers, Let’s Encrypt TLS, HTTP 410 status, and the specific page title) into threat‑intel feeds. Continuous re‑query of passive DNS and certificate transparency logs is advised to detect potential reuse of the IP or certificate by other malicious actors.
Signaux de sécurité
Processus de réponse aux menaces Pipeline
Statut de la liste de blocage publique
Capture enregistrée
Informations sur les domaines
Détails techniquesDNS, SAN SSL, horodatages
Technologies · 2 identified
Cloudflare is a web-infrastructure and website-security company, providing content-delivery-network services, DDoS mitigation, Internet security, and distributed domain-name-server services.
www.cloudflare.com Confiance à 100 %HTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org Confiance à 100 %Analyse VirusTotal
Preuves archivées
Données factuelles et rapports externes
Ce site vous a-t-il affecté ?
Si vous avez saisi des informations d'identification de compte, des informations personnelles ou de paiement, ou téléchargé un fichier à partir de ce domaine, agissez immédiatement. Vous trouverez ci-dessous des ressources pour vous aider à signaler l'incident et à vous protéger.
Signalez-le à vos autorités locales
Sélectionnez votre pays pour obtenir contacts officiels en matière de cybercriminalité ou créer un projet de plainte →.
Vérifier n'importe quel domaine
Analyse des menaces à l'aide de listes de blocage stockées, de WHOIS, de DNS et de preuves d'analyse publique
Scanner maintenantSignaler une tentative d'hameçonnage
Signalez les domaines suspects à notre base de données des menaces — protégez la communauté
SignalerFlux d'alertes en temps réel
Rapports de phishing récents et changements de disponibilité observés
SurveillerRestez informés, restez en sécurité
Surveillez les menaces en temps réel ou signalez cette alerte si vous pensez qu'il s'agit d'un faux positif