bafybeigdc66io3yev7awofrteoyay6ghsx2jzqebhsim4sza26bvwm7ytq[.]ipfs[.]dweb[.]link
“CARV - Modular Data Layer for Gaming and AI”
bafybeigdc66io3yev7awofrteoyay6ghsx2jzqebhsim4sza26bvwm7ytq.ipfs.dweb.link — असत्यापित. ब्रांड प्रतिरूपण: Revolut; घोटाले का प्रकार: Impersonation. साक्ष्य सारांश: VirusTotal 13/91 (alphaMountain.ai, BitDefender, ESET, Emsisoft, G-Data); 1 external blocklist match (ScamSniffer); CF Radar malicious; PhishDestroy score 94/100. रजिस्ट्रार: CSC.
मूल फॉरेंसिक रिकॉर्ड सुरक्षित रखने के लिए नीचे का विस्तृत PhishDestroy AI विश्लेषण अंग्रेज़ी में रखा गया है।
This domain, bafybeigdc66io3yev7awofrteoyay6ghsx2jzqebhsim4sza26bvwm7ytq.ipfs.dweb.link, is flagged as an active high-risk brand impersonation threat targeting Revolut. Infrastructure analysis reveals the domain is hosted on IPFS and resolves to 2602:fea2:2::2, with Cloudflare nameservers (clarissa.ns.cloudflare.com, tate.ns.cloudflare.com) and a Let's Encrypt SSL certificate. The domain was created on February 24, 2017, and is registered through CSC Corporate Domains, Inc. Despite its age, it currently serves a page titled 'CARV - Modular Data Layer for Gaming and AI,' which does not align with the targeted brand, suggesting either misdirection or a compromised legitimate resource repurposed for phishing. Security vendors flag this domain, with 10 out of 95 detections on VirusTotal, and it appears on two security blocklists (PhishDestroy, ScamSniffer). The HTTP 301 redirect indicates potential redirection to another malicious endpoint, though the final destination remains unconfirmed. Technologies detected include IPFS, Google Tag Manager, Cloudflare, and HTTP/3, which may be leveraged to evade detection or track victims. Defenders should treat this domain as active and high-risk. Immediate actions include blocking resolution at the DNS level, monitoring for connections to the associated IP (2602:fea2:2::2), and investigating any internal access attempts. The discrepancy between the page title and the impersonated brand warrants further analysis to determine if this is a phishing kit, a compromised IPFS resource, or part of a broader campaign. Given the domain's age and infrastructure, retrospective log analysis may identify prior compromise activity.
सुरक्षा संकेत
नेटवर्क सुरक्षा इंटेलिजेंस
धमकी प्रतिक्रिया पाइपलाइन
सार्वजनिक ब्लॉकलिस्ट स्थिति
तकनीकें · 4 identified
IPFS is a peer-to-peer hypermedia protocol that provides a distributed hypermedia web.
ipfs.tech 100% विश्वासGoogle Tag Manager is a tag management system (TMS) that allows you to quickly and easily update measurement codes and related code fragments collectively known as tags on your website or mobile app.
www.google.com 100% विश्वासCloudflare is a web-infrastructure and website-security company, providing content-delivery-network services, DDoS mitigation, Internet security, and distributed domain-name-server services.
www.cloudflare.com 100% विश्वासHTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org 100% विश्वासवायरसटोटल विश्लेषण
संग्रहीत साक्ष्य
साइट कॉन्फ़िगरेशन विश्लेषण
साक्ष्य और बाहरी रिपोर्टें
क्या आप इस साइट से प्रभावित हुए?
यदि आपने खाता क्रेडेंशियल, व्यक्तिगत या भुगतान जानकारी दर्ज की है, या इस डोमेन से कोई फ़ाइल डाउनलोड की है, तो तुरंत कार्रवाई करें। घटना की रिपोर्ट करने और अपनी सुरक्षा करने में आपकी सहायता के लिए नीचे संसाधन दिए गए हैं।
अपने स्थानीय अधिकारियों को रिपोर्ट करें
आधिकारिक साइबर अपराध संपर्क, या एक शिकायत ड्राफ्ट बनाएं → प्राप्त करने के लिए अपना देश चुनें।
किसी भी डोमेन की जाँच करें
संग्रहीत ब्लॉकलिस्ट, WHOIS, DNS और सार्वजनिक स्कैन साक्ष्य का उपयोग करके खतरे का विश्लेषण
अभी स्कैन करेंफ़िशिंग की रिपोर्ट करें
संदिग्ध डोमेन हमारे थ्रेट डेटाबेस में जमा करें — समुदाय की सुरक्षा करें
रिपोर्ट करेंसीधा खतरा फीड
हाल की फ़िशिंग रिपोर्टें और उपलब्धता में परिवर्तन देखे गए
निगरानी करेंजानकारी में रहें, सुरक्षित रहें
लाइव खतरों की निगरानी करें या यदि आपको लगता है कि यह एक गलत सकारात्मक है तो इस लिस्टिंग को चुनौती दें।