bafkreihozxz6uz57gmezial5t3ysbxi2zyanve27ndf23dtmljw2zg5qga[.]ipfs[.]dweb[.]link
“Rackspace Webmail: Hosted Email for Business”
bafkreihozxz6uz57gmezial5t3ysbxi2zyanve27ndf23dtmljw2zg5qga.ipfs.dweb.link — सामग्री अनुपलब्ध. ब्रांड प्रतिरूपण: Rackspace; घोटाले का प्रकार: Brand Impersonation. साक्ष्य सारांश: VirusTotal 19/93 (ADMINUSLabs, alphaMountain.ai, BitDefender, CRDF, CyRadar); URLScan malicious verdict; CF Radar malicious; PhishDestroy score 95/100. रजिस्ट्रार: CSC.
मूल फॉरेंसिक रिकॉर्ड सुरक्षित रखने के लिए नीचे का विस्तृत PhishDestroy AI विश्लेषण अंग्रेज़ी में रखा गया है।
This domain, bafkreihozxz6uz5.ipfs.dweb.link, represents a targeted brand impersonation threat designed to harvest enterprise credentials by mimicking Rackspace Webmail services. Analysis indicates the infrastructure presents a fraudulent login portal titled 'Rackspace Webmail: Hosted Email for Business,' a direct replication of the legitimate Rackspace webmail interface. The intent is to deceive employees or customers into submitting corporate email credentials, enabling subsequent unauthorized access to internal communications, sensitive data, or further lateral movement within compromised networks. Credential theft of this nature often serves as an initial access vector for business email compromise, data exfiltration, or ransomware deployment, particularly in enterprise environments where cloud-based email services are widely adopted. Infrastructure analysis reveals multiple high-confidence indicators supporting the malicious classification of this domain. The resource is hosted on IP address 209.94.90.3, originating from AS40680 (Protocol Labs) in the United States, and uses a Let's Encrypt SSL certificate (identifier E7) to lend an appearance of legitimacy. The domain was registered through CSC Corporate Domains, Inc. on February 21, 2026, though the creation date appears anomalous and may reflect backdating or administrative manipulation. Security telemetry shows the domain is flagged by 19 out of 95 security vendors on VirusTotal, with additional presence on one active blocklist. The combination of brand impersonation, anomalous registration data, and multi-source detection strongly suggests orchestrated malicious activity rather than benign misconfiguration. Users who accessed or entered credentials on bafkreihozxz6uz5.ipfs.dweb.link should immediately take corrective action to mitigate potential compromise. All submitted credentials must be considered exposed and should be reset across all associated accounts, particularly corporate email and single sign-on systems. Enable multi-factor authentication where available, and monitor affected accounts for unauthorized access or anomalous activity such as unexpected password reset emails, login attempts from unfamiliar locations, or suspicious email forwarding rules. Organizations should review logs for connections to 209.94.90.3 and the domain in question, and consider isolating any endpoints that interacted with the resource. Given the elevated risk profile, affected users are advised to conduct a full security review of their email environment and report the incident to internal security teams or relevant incident response authorities.
नेटवर्क सुरक्षा इंटेलिजेंस
धमकी प्रतिक्रिया पाइपलाइन
सार्वजनिक ब्लॉकलिस्ट स्थिति
तकनीकें · 2 identified
Web infrastructure and security company providing CDN, DDoS mitigation, and DNS services.
www.cloudflare.comThird major version of HTTP protocol, built on QUIC for faster, more reliable connections.
वायरसटोटल विश्लेषण
संग्रहीत साक्ष्य
साक्ष्य और बाहरी रिपोर्टें
क्या आप इस साइट से प्रभावित हुए?
यदि आपने खाता क्रेडेंशियल, व्यक्तिगत या भुगतान जानकारी दर्ज की है, या इस डोमेन से कोई फ़ाइल डाउनलोड की है, तो तुरंत कार्रवाई करें। घटना की रिपोर्ट करने और अपनी सुरक्षा करने में आपकी सहायता के लिए नीचे संसाधन दिए गए हैं।
अपने स्थानीय अधिकारियों को रिपोर्ट करें
आधिकारिक साइबर अपराध संपर्क, या एक शिकायत ड्राफ्ट बनाएं → प्राप्त करने के लिए अपना देश चुनें।
किसी भी डोमेन की जाँच करें
संग्रहीत ब्लॉकलिस्ट, WHOIS, DNS और सार्वजनिक स्कैन साक्ष्य का उपयोग करके खतरे का विश्लेषण
अभी स्कैन करेंफ़िशिंग की रिपोर्ट करें
संदिग्ध डोमेन हमारे थ्रेट डेटाबेस में जमा करें — समुदाय की सुरक्षा करें
रिपोर्ट करेंसीधा खतरा फीड
हाल की फ़िशिंग रिपोर्टें और उपलब्धता में परिवर्तन देखे गए
निगरानी करेंजानकारी में रहें, सुरक्षित रहें
लाइव खतरों की निगरानी करें या यदि आपको लगता है कि यह एक गलत सकारात्मक है तो इस लिस्टिंग को चुनौती दें।