bafybeieo4yatzqc2xgn26pfjyxk6qhmvevorblcwqvk5pmivmmy254rxj4[.]ipfs[.]infura-ipfs[.]io
“Webmail”
bafybeieo4yatzqc2xgn26pfjyxk6qhmvevorblcwqvk5pmivmmy254rxj4.ipfs.infura-ipfs.io — Contenu indisponible. Usurpation de l'identité de la marque : Genericemail. Résumé des preuves: VirusTotal 18/95 (BitDefender, CRDF, CyRadar, ESET, Emsisoft); URLScan malicious verdict; CF Radar malicious; PhishDestroy score 100/100. Bureau d’enregistrement: GANDI SAS.
L’analyse détaillée de PhishDestroy AI reste en anglais afin de préserver le relevé forensique original.
This domain, bafybeieo4yatzqc2xgn26pfjyxk6qhmvevorblcwqvk5pmivmmy254rxj4.ipfs.infura-ipfs.io, poses an elevated-risk generic phishing threat specifically targeting webmail credentials. Analysis of the page title, "Webmail," indicates an attempt to mimic legitimate email login portals, tricking users into submitting sensitive authentication details. Such infrastructure is commonly used in credential harvesting campaigns, where stolen login data is later exploited for unauthorized access, data exfiltration, or further phishing attacks against contacts. Evidence supporting this assessment includes detection by 18 out of 95 security vendors on VirusTotal, registration through GANDI SAS since January 30, 2020, and presence on two security blocklists. The domain resolves to the IP address 209.94.90.3, hosted under AS40680 (Protocol Labs) in the United States. The SSL certificate, issued by Amazon RSA 2048 M02, does not mitigate the malicious intent, as phishing domains frequently leverage valid certificates to appear legitimate. The domain’s inclusion in PhishDestroy and PhishingDB further corroborates its classification as malicious infrastructure. Users who visited this domain or entered credentials should immediately reset passwords for any accounts accessed from the same device or network. Enable multi-factor authentication (MFA) on all critical accounts to prevent unauthorized access. Monitor financial and communication platforms for unusual activity, as stolen credentials may be used in follow-up attacks. If corporate credentials were exposed, report the incident to internal security teams for containment and forensic analysis. Avoid interacting with any links or attachments from suspicious emails, and verify the legitimacy of webmail portals by checking domain names and SSL certificate details before entering credentials.
Signaux de sécurité
Renseignements sur la sécurité réseau
Processus de réponse aux menaces Pipeline
Statut de la liste de blocage publique
Technologies · 2 identified
Amazon Web Services (AWS) is a comprehensive cloud services platform offering compute power, database storage, content delivery and other functionality.
aws.amazon.com Confiance à 100 %AWS Certificate Manager is a service that lets you easily provision, manage, and deploy public and private Secure Sockets Layer/Transport Layer Security (SSL/TLS) certificates for use with AWS services and your internal connected resources.
aws.amazon.com Confiance à 100 %Analyse VirusTotal
Données factuelles et rapports externes
Ce site vous a-t-il affecté ?
Si vous avez saisi des informations d'identification de compte, des informations personnelles ou de paiement, ou téléchargé un fichier à partir de ce domaine, agissez immédiatement. Vous trouverez ci-dessous des ressources pour vous aider à signaler l'incident et à vous protéger.
Signalez-le à vos autorités locales
Sélectionnez votre pays pour obtenir contacts officiels en matière de cybercriminalité ou créer un projet de plainte →.
Vérifier n'importe quel domaine
Analyse des menaces à l'aide de listes de blocage stockées, de WHOIS, de DNS et de preuves d'analyse publique
Scanner maintenantSignaler une tentative d'hameçonnage
Signalez les domaines suspects à notre base de données des menaces — protégez la communauté
SignalerFlux d'alertes en temps réel
Rapports de phishing récents et changements de disponibilité observés
SurveillerRestez informés, restez en sécurité
Surveillez les menaces en temps réel ou signalez cette alerte si vous pensez qu'il s'agit d'un faux positif