bafybeiaoulkqm54mkpjy5t7idjlc2wxddyj7a4cpdrpi4reejwkd4gphke[.]ipfs[.]dweb[.]link
“Lets GOU! – Goummunity Takeover”
bafybeiaoulkqm54mkpjy5t7idjlc2wxddyj7a4cpdrpi4reejwkd4gphke.ipfs.dweb.link — असत्यापित. साक्ष्य सारांश: VirusTotal 16/91 (alphaMountain.ai, BitDefender, Chong Lua Dao, CRDF, CyRadar); 1 external blocklist match (ScamSniffer); PhishDestroy score 100/100. रजिस्ट्रार: CSC.
मूल फॉरेंसिक रिकॉर्ड सुरक्षित रखने के लिए नीचे का विस्तृत PhishDestroy AI विश्लेषण अंग्रेज़ी में रखा गया है।
The domain bafybeiaoulkqm54mkpjy5t7idjlc2wxddyj7a4cpdrpi4reejwkd4gphke.ipfs.dweb.link is currently active and has been identified as a generic phishing operation. Infrastructure analysis shows the domain resolves to the IP address 209.94.90.3, which is hosted in the United States and belongs to AS40680 (Protocol Labs). The site is served through Cloudflare, using HTTP/3, and the authoritative nameservers are clarissa.ns.cloudflare.com and tate.ns.cloudflare.com. A Let’s Encrypt certificate (Issuer: E7) secures the HTTPS connection, but the HTTP response returns a 301 redirect, indicating a possible attempt to forward visitors to a malicious landing page.
The page title observed is "Lets GOU! – Goummunity Takeover," offering no additional context about the spoofed brand or content. Registrant information lists CSC Corporate Domains, Inc. as the registrar, and the domain was originally created on 24 February 2017, suggesting long‑term reuse of the namespace. Reputation signals are poor: Scamadviser assigns a trust score of 20 out of 100, and the domain appears on two security blocklists (PhishDestroy and ScamSniffer).
VirusTotal analysis reports 12 of 91 scanning engines flag the domain, reinforcing the malicious classification. While the exact phishing payload or credential‑harvesting mechanism remains unverified, the convergence of a low trust score, multiple vendor detections, and blocklist listings provides strong evidence of malicious intent. Defenders should block the domain at network perimeter, update URL filtering and threat intelligence feeds, and monitor for any related activity originating from the same IP or Cloudflare edge. Continuous re‑evaluation is advised, as the site may evolve its tactics or host additional malicious content.
सुरक्षा संकेत
धमकी प्रतिक्रिया पाइपलाइन
सार्वजनिक ब्लॉकलिस्ट स्थिति
तकनीकें · 2 identified
Cloudflare is a web-infrastructure and website-security company, providing content-delivery-network services, DDoS mitigation, Internet security, and distributed domain-name-server services.
www.cloudflare.com 100% विश्वासHTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org 100% विश्वासवायरसटोटल विश्लेषण
संग्रहीत साक्ष्य
साक्ष्य और बाहरी रिपोर्टें
क्या आप इस साइट से प्रभावित हुए?
यदि आपने खाता क्रेडेंशियल, व्यक्तिगत या भुगतान जानकारी दर्ज की है, या इस डोमेन से कोई फ़ाइल डाउनलोड की है, तो तुरंत कार्रवाई करें। घटना की रिपोर्ट करने और अपनी सुरक्षा करने में आपकी सहायता के लिए नीचे संसाधन दिए गए हैं।
अपने स्थानीय अधिकारियों को रिपोर्ट करें
आधिकारिक साइबर अपराध संपर्क, या एक शिकायत ड्राफ्ट बनाएं → प्राप्त करने के लिए अपना देश चुनें।
किसी भी डोमेन की जाँच करें
संग्रहीत ब्लॉकलिस्ट, WHOIS, DNS और सार्वजनिक स्कैन साक्ष्य का उपयोग करके खतरे का विश्लेषण
अभी स्कैन करेंफ़िशिंग की रिपोर्ट करें
संदिग्ध डोमेन हमारे थ्रेट डेटाबेस में जमा करें — समुदाय की सुरक्षा करें
रिपोर्ट करेंसीधा खतरा फीड
हाल की फ़िशिंग रिपोर्टें और उपलब्धता में परिवर्तन देखे गए
निगरानी करेंजानकारी में रहें, सुरक्षित रहें
लाइव खतरों की निगरानी करें या यदि आपको लगता है कि यह एक गलत सकारात्मक है तो इस लिस्टिंग को चुनौती दें।