सुरक्षा रिपोर्ट पर जाएँ
⚠️
इस डोमेन को दुर्भावनापूर्ण के रूप में चिह्नित किया गया है।
सुरक्षा इंजन एक पहचान की रिपोर्ट कर रहे हैं: 17। अत्यधिक सावधानी बरतें - क्रेडेंशियल या व्यक्तिगत जानकारी दर्ज न करें।
डोमेन सुरक्षा और ख़तरे की आसूचना

bafkreigitj7uo2ip62qmnl6n4tf4ammrx3kiqxl7zz7sdqy66pc7yemygi[.]ipfs[.]dweb[.]link

“EmailLogin”

धमकी भरा फैसला गंभीर 100/100 साक्ष्य स्कोर
उपलब्धता सामग्री अनुपलब्ध नवीनतम अवलोकन में सामग्री अनुपलब्ध थी
वायरस का कुल पता लगाना: 17/94 URLQuery threat systems: 4 alerts घोटाले का प्रकार: Credential Phishing
25/04/2026 CDN
रिपोर्ट सारांश

bafkreigitj7uo2ip62qmnl6n4tf4ammrx3kiqxl7zz7sdqy66pc7yemygi.ipfs.dweb.link — सामग्री अनुपलब्ध. घोटाले का प्रकार: Credential Phishing. साक्ष्य सारांश: VirusTotal 17/94 (ADMINUSLabs, alphaMountain.ai, Chong Lua Dao, CRDF, CyRadar); URLQuery 4 alerts; PhishDestroy score 100/100. रजिस्ट्रार: CSC.

मूल फॉरेंसिक रिकॉर्ड सुरक्षित रखने के लिए नीचे का विस्तृत PhishDestroy AI विश्लेषण अंग्रेज़ी में रखा गया है।

साक्ष्य सारांश
आलोचनात्मक
संदर्भ
D6590403
स्कोर
100/100

PhishDestroy identifies an active crypto drainer domain hosted via IPFS at bafkreigitj7uo2ip62qmnl6n4tf4ammrx3kiqxl7zz7sdqy66pc7yemygi.ipfs.dweb.link. The site was flagged under a generic phishing threat vector, specifically designed to intercept cryptocurrency wallet credentials or initiate unauthorized transfers. The domain is currently under investigation but remains accessible and potentially harmful to unprotected users. Given the absence of detections on VirusTotal and the use of a legitimate SSL certificate from Let's Encrypt, it poses a deceptive appearance of legitimacy while operating outside standard security oversight. This combination of factors makes it a high-risk entry point for crypto asset theft, particularly for users interacting with decentralized storage or blockchain-based services. This domain exhibits several technical indicators that align with advanced phishing campaigns. It resolves to IP address 209.94.90.2, a known hosting infrastructure with limited historical trust scores based on domain age and registrar data. The domain was created on February 24, 2017, which may suggest an attempt to appear established, though this is not uncommon for reused or repurposed domains in phishing operations. Registration through CSC Corporate Domains, Inc. adds a layer of legitimacy due to the registrar's corporate focus, potentially masking malicious intent. VirusTotal currently shows 17/95 detections, indicating that mainstream security tools have not yet flagged the domain, likely due to its recent or highly targeted deployment. The presence of a Let's Encrypt SSL certificate further enhances its credibility, exploiting user trust in HTTPS indicators. These characteristics suggest a sophisticated threat actor leveraging both technical and psychological vectors to deceive users. To mitigate exposure to this crypto drainer threat, users should immediately block the associated IP 209.94.90.2 at the network perimeter and disable or restrict access to IPFS gateway links referencing this CID (bafkreigitj7uo2ip62qmnl6n4tf4ammrx3kiqxl7zz7sdqy66pc7yemygi). Organizations should update browser policies to disallow direct access to IPFS dweb.link domains unless explicitly whitelisted. Enable advanced threat detection tools that monitor for wallet transaction patterns or unauthorized signature requests, as crypto drainers often rely on silent approvals. Users should verify destination domains manually, avoid interacting with unsolicited IPFS links, and use hardware wallets or isolated signing environments for high-value transactions. Given the 17/95 detection rate, this threat represents a blind spot in traditional defenses and requires proactive threat intelligence integration and user education to prevent asset loss.

VirusTotal
VirusTotal
17 det.
URLQuery
यूआरएलक्वेरी
4 threat alerts
DNS Security
3/12
URLScan
यूआरएलस्कैन
TLS प्रमाणपत्र
Let's Encrypt
Hosting
IPFS Gateway
आयु
4 mo
देखी गई स्थिति
सामग्री अनुपलब्ध
PhishDestroy
विनाश सूची
सूचीबद्ध
डेटा कवरेज VirusTotal 17 / 94 यूआरएलक्वेरी 4 threat-system alerts फ़िशस्टैट्स checked — no match recorded ओटीएक्स no community references सीएफ रडार scan completed URLScan capture संग्रहित रिपोर्ट URLScan verdict विश्लेषण पूरा हुआ डीएनएस ब्लॉक 3/12 TLS valid certificate, 58d कौन है 4 mo old स्क्रीनशॉट 3 captures · 3 sources चेन पुनर्निर्देशित करें जांच नहीं की गई
नेटवर्क सुरक्षा इंटेलिजेंस
DNS Provider Blocks 3 / 12
Controld Adblock Controld Family Controld Malware
Threat Detection Systems 4 alerts
Detection System Indicator Verdict Alert
OpenDNS bafkreigitj7uo2ip62qmnl6n4tf4ammrx3kiqxl7zz7sdqy66pc7yemygi.ipfs.dweb.link phishing Phishing Block
DNS4EU bafkreigitj7uo2ip62qmnl6n4tf4ammrx3kiqxl7zz7sdqy66pc7yemygi.ipfs.dweb.link malicious Sinkholed
Hagezi Threat Feed www.kosherbh.com malicious Sinkholed
DNS4EU www.kosherbh.com malicious Sinkholed
Free Hosting Detected IPFS Gateway
This domain is hosted on IPFS Gateway (decentralized hosting (ipfs)). Decentralized hosting makes content removal extremely difficult, making it a preferred infrastructure for phishing and scam operat

धमकी प्रतिक्रिया पाइपलाइन

खोज
Checks
Reports
उपलब्धता
14/15

सार्वजनिक ब्लॉकलिस्ट स्थिति

सहेजा गया कैप्चर

डोमेन इंटेलिजेंस

डोमेन
URLScan Verdict विश्लेषण पूरा हुआ score 0 report ↗
सर्वर / ASN cloudflare · AS40680 Protocol Labs
IP Context Cloudflare shared edge origin IP hidden एज-आईपी प्रतिष्ठा इस डोमेन के लिए जिम्मेदार नहीं है।
प्लेटफ़ॉर्म प्रदाता CSC US(US)
दुरुपयोग संपर्कtldsupport@cscinfo.com, abuse@ipfs.io
IP पता 209.94.90.2 CDN
भौगोलिक स्थानUS San Francisco, US
नेटवर्कAS40680 · Protocol Labs
रिवर्स IPviewdns.info → rapiddns.io →
मूल आईपी सीडीएन प्रॉक्सी के पीछे छिपा हुआ है। किनारे के पते के लिए रिवर्स-आईपी परिणामों में असंबंधित किरायेदार शामिल हैं; मूल का पता लगाने के लिए निष्क्रिय DNS या प्रमाणपत्र-पारदर्शिता डेटा की आवश्यकता होती है।
पहली अनुपलब्धता तक का समय 3 days
हम क्या मापते हैं पहली संग्रहीत दुरुपयोग रिपोर्ट से लेकर पहली बार अवलोकन तक कि सामग्री अनुपलब्ध थी, बीता हुआ समय। इससे कारण स्थापित नहीं होता.
प्रत्येक रिपोर्ट में क्या शामिल है संग्रहीत आउटगोइंग-रिपोर्ट रिकॉर्ड उस समय उपलब्ध साक्ष्य का संदर्भ दे सकते हैं, जैसे विक्रेता के फैसले, पंजीकरण डेटा, होस्टिंग विवरण, वर्गीकरण, या स्क्रीनशॉट। यह पृष्ठ किसी प्राप्तकर्ता द्वारा वितरित सटीक पेलोड, रसीद, पावती या कार्रवाई का अनुमान नहीं लगाता है।
तकनीकी विवरणडीएनएस, एसएसएल एसएएन, टाइमस्टैम्प
पहली बार पता चला25/04/2026
IoC Extractionscanned 01/08/20260 wallet · 0 Telegram IoCs
Submitted URLhttp://bafkreigitj7uo2ip62qmnl6n4tf4ammrx3kiqxl7zz7sdqy66pc7yemygi.ipfs.dweb.link/
नेमसर्वरtate.ns.cloudflare.com
TLS Fingerprint
TLS Observationvalid from 25/03/2026scanned 25/04/2026
TLS SAN Domainsdweb.link
Favicon Hash
पेज शीर्षक
EmailLogin
TLS प्रमाणपत्र
Valid transport encryption · जारीकर्ता Let's Encrypt · valid for 58 days
तकनीकें · 3 identified
IPFS
Network storage

IPFS is a peer-to-peer hypermedia protocol that provides a distributed hypermedia web.

ipfs.tech 100% विश्वास
Cloudflare
CDN

Cloudflare is a web-infrastructure and website-security company, providing content-delivery-network services, DDoS mitigation, Internet security, and distributed domain-name-server services.

www.cloudflare.com 100% विश्वास
HTTP/3
Miscellaneous

HTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.

httpwg.org 100% विश्वास
Detected via क्लाउडफ्लेयर रडार · Wappalyzer engine
इस डोमेन की रिपोर्ट करें सबूत जमा करें और दूसरों की सुरक्षा में मदद करें

वायरसटोटल विश्लेषण

17 / 94 सुरक्षा विक्रेताओं ने इस डोमेन को चिह्नित किया
View on VT
Last analyzed
ADMINUSLabs
alphaMountain.ai
Chong Lua Dao
CRDF
साइरेडार
Emsisoft
Forcepoint ThreatSeeker
G-Data
Gridinsoft
कास्परस्की
LevelBlue
Lionic
MalwareURL
नेटक्राफ्ट
ओपनफ़िश
Phishing Database
वेबरूट

संग्रहीत साक्ष्य

Wayback Machine Snapshot
साक्ष्य समीक्षा के लिए एक ऐतिहासिक स्नैपशॉट उपलब्ध है
View Archive
साइट प्रदर्शन विश्लेषण

Google PageSpeed Insights — mobile performance audit of bafkreigitj7uo2ip62qmnl6n4tf4ammrx3kiqxl7zz7sdqy66pc7yemygi.ipfs.dweb.link · checked Apr 25, 2026

87
Needs Work
Performance
FCP
3.16s
First Contentful Paint
LCP
3.16s
Largest Contentful Paint
CLS
0.007
Cumulative Layout Shift
TBT
0ms
Total Blocking Time
SI
3.16s
Speed Index
Powered by Google PageSpeed Insights · Mobile strategy · Scores: 90-100 Good 50-89 Needs Work 0-49 Poor

साक्ष्य और बाहरी रिपोर्टें

क्या आप इस साइट से प्रभावित हुए?

If credentials were compromised, report immediately. Do not engage with recovery scammers.

यदि आपने खाता क्रेडेंशियल, व्यक्तिगत या भुगतान जानकारी दर्ज की है, या इस डोमेन से कोई फ़ाइल डाउनलोड की है, तो तुरंत कार्रवाई करें। घटना की रिपोर्ट करने और अपनी सुरक्षा करने में आपकी सहायता के लिए नीचे संसाधन दिए गए हैं।

यूरोपोल
अपने ईयू देश के लिए आधिकारिक रिपोर्टिंग चैनल ढूंढें
National police directory
रिकवरी ठगों से सावधान रहें! अपराधी जांचकर्ता, वकील या रिकवरी एजेंट होने का नाटक करते हुए पीड़ितों से दोबारा संपर्क कर सकते हैं। अग्रिम शुल्क का भुगतान न करें या क्रेडेंशियल साझा न करें। रिकवरी धोखाधड़ी के बारे में और जानें →

अपने स्थानीय अधिकारियों को रिपोर्ट करें

आधिकारिक साइबर अपराध संपर्क, या एक शिकायत ड्राफ्ट बनाएं → प्राप्त करने के लिए अपना देश चुनें।

97-देश निर्देशिका
एआई-सहायता प्राप्त ड्राफ्ट - घटना विवरण एआई प्रदाता द्वारा संसाधित किया जाता है इसकी स्वयं समीक्षा करें और सबमिट करें

किसी भी डोमेन की जाँच करें

संग्रहीत ब्लॉकलिस्ट, WHOIS, DNS और सार्वजनिक स्कैन साक्ष्य का उपयोग करके खतरे का विश्लेषण

अभी स्कैन करें

फ़िशिंग की रिपोर्ट करें

संदिग्ध डोमेन हमारे थ्रेट डेटाबेस में जमा करें — समुदाय की सुरक्षा करें

रिपोर्ट करें

सीधा खतरा फीड

हाल की फ़िशिंग रिपोर्टें और उपलब्धता में परिवर्तन देखे गए

निगरानी करें

जानकारी में रहें, सुरक्षित रहें

लाइव खतरों की निगरानी करें या यदि आपको लगता है कि यह एक गलत सकारात्मक है तो इस लिस्टिंग को चुनौती दें।

सीधा खतरा फीड इस लिस्टिंग के खिलाफ अपील करें
HTML · IFRAME

इस रिपोर्ट को एम्बेड करें

इस थ्रेट इंटेलिजेंस को अपनी वेबसाइट या ब्लॉग पर साझा करें।

embed.html
<iframe
  src="https://phishdestroy.io/hi/embed/domain/bafkreigitj7uo2ip62qmnl6n4tf4ammrx3kiqxl7zz7sdqy66pc7yemygi.ipfs.dweb.link"
  title="PhishDestroy threat report for bafkreigitj7uo2ip62qmnl6n4tf4ammrx3kiqxl7zz7sdqy66pc7yemygi.ipfs.dweb.link"
  width="100%" height="320"
  loading="lazy"
  referrerpolicy="no-referrer"
  sandbox="allow-same-origin allow-popups allow-popups-to-escape-sandbox"
  style="border:0;border-radius:12px;max-width:100%"
></iframe>