bafybeihx7zpcybjq34jdy2tk2tjh6q5lw6l32p22pluszrqclrjuharkj4[.]ipfs[.]dweb[.]link
“410 Gone”
bafybeihx7zpcybjq34jdy2tk2tjh6q5lw6l32p22pluszrqclrjuharkj4.ipfs.dweb.link — Contenu indisponible. Résumé des preuves: VirusTotal 14/95 (ADMINUSLabs, alphaMountain.ai, BitDefender, CRDF, CyRadar); Google Safe Browsing flagged; PhishDestroy score 97/100. Bureau d’enregistrement: CSC.
L’analyse détaillée de PhishDestroy AI reste en anglais afin de préserver le relevé forensique original.
Analysis as of July 24, 2026 indicates that the domain bafybeihx7zpcybjq34jdy2tk2tjh6q5lw6l32p22pluszrqclrjuharkj4.ipfs.dweb.link is associated with a high‑risk generic phishing operation. The site currently returns an HTTP 410 Gone status and its page title is listed as "410 Gone," suggesting the content has been removed or deliberately disabled. The domain was registered on February 24, 2017 through CSC Corporate Domains, Inc., and its DNS resolution points to IP address 209.94.90.2, which is owned by Protocol Labs (AS40680) and geolocated to the United States. Cloudflare provides the authoritative nameservers clarissa.ns.cloudflare.com and tate.ns.cloudflare.com, and the hosting environment advertises support for HTTP/3.
A Let's Encrypt certificate (E7) is present, confirming the use of valid TLS for HTTPS connections. Google Safe Browsing has flagged the domain for social engineering, and PhishDestroy lists it as blocked. VirusTotal reports that 14 of 95 scanned security vendors have flagged the domain, indicating a consensus of malicious behavior among multiple antivirus engines. The site appears on a single external blocklist and has a Scamadviser trust score of 1 out of 100, reinforcing its classification as highly untrustworthy.
Uncertainty remains regarding the specific phishing campaign payload, the targeted brand or credential set, and whether any active phishing pages were previously hosted prior to the 410 response. Defenders should continue to monitor the domain’s IP and DNS records for any reactivation, enforce blocklist rules to deny traffic to 209.94.90.2, and incorporate the domain hash into threat‑intel feeds. Organizations using web filtering should retain the Google Safe Browsing and PhishDestroy alerts, and SOC analysts should treat any future activity from this domain as a high‑confidence indicator of phishing intent.
Signaux de sécurité
Processus de réponse aux menaces Pipeline
Statut de la liste de blocage publique
Technologies · 2 identified
Web infrastructure and security company providing CDN, DDoS mitigation, and DNS services.
www.cloudflare.comThird major version of HTTP protocol, built on QUIC for faster, more reliable connections.
Analyse VirusTotal
Preuves archivées
Analyse de la configuration du site
Données factuelles et rapports externes
Ce site vous a-t-il affecté ?
Si vous avez saisi des informations d'identification de compte, des informations personnelles ou de paiement, ou téléchargé un fichier à partir de ce domaine, agissez immédiatement. Vous trouverez ci-dessous des ressources pour vous aider à signaler l'incident et à vous protéger.
Signalez-le à vos autorités locales
Sélectionnez votre pays pour obtenir contacts officiels en matière de cybercriminalité ou créer un projet de plainte →.
Vérifier n'importe quel domaine
Analyse des menaces à l'aide de listes de blocage stockées, de WHOIS, de DNS et de preuves d'analyse publique
Scanner maintenantSignaler une tentative d'hameçonnage
Signalez les domaines suspects à notre base de données des menaces — protégez la communauté
SignalerFlux d'alertes en temps réel
Rapports de phishing récents et changements de disponibilité observés
SurveillerRestez informés, restez en sécurité
Surveillez les menaces en temps réel ou signalez cette alerte si vous pensez qu'il s'agit d'un faux positif