bafybeibvd45o3zcj7cwhqzszpwbtfyic4p7spfed2kxuizsh4qtdmt2gom[.]ipfs[.]infura-ipfs[.]io
“Webmail”
bafybeibvd45o3zcj7cwhqzszpwbtfyic4p7spfed2kxuizsh4qtdmt2gom.ipfs.infura-ipfs.io — Konten tidak tersedia. Peniruan identitas merek: Genericemail. Ringkasan bukti: VirusTotal 16/95 (BitDefender, CyRadar, ESET, Emsisoft, Forcepoint ThreatSeeker); URLScan malicious verdict; CF Radar malicious; PhishDestroy score 95/100. Registrar: GANDI SAS.
Analisis terperinci PhishDestroy AI di bawah tetap berbahasa Inggris untuk menjaga catatan forensik asli.
This domain, bafybeibvd45o3zcj7cwhqzszpwbtfyic4p7spfed2kxuizsh4qtdmt2gom.ipfs.inffs.infura-ipfs.io, is identified as a credential theft operation impersonating Webmail services. Analysis indicates the infrastructure was designed to harvest login credentials through a fraudulent Webmail interface, with no evidence of crypto drainer functionality or brand-specific impersonation beyond generic email service spoofing. The page title "Webmail" and absence of additional brand markers suggest a broad, opportunistic credential harvesting campaign rather than targeted brand abuse. Infrastructure analysis reveals the domain was registered via GANDI SAS on January 30, 2020, and resolves to the IP address 209.94.90.3, hosted under AS40680 (Protocol Labs). The SSL certificate is issued by Amazon RSA 2048 M02, a common provider for both legitimate and malicious domains. The domain is flagged by 16 out of 95 security vendors on VirusTotal, appears on two security blocklists, and is explicitly blocked by PhishDestroy and PhishingDB. No Google Safe Browsing (GSB) detection was noted in the available data, though this may reflect delayed synchronization rather than absence of malicious classification. As of the latest verification, the domain has been taken offline, likely due to hosting provider intervention or registrar enforcement. However, the underlying infrastructure—including the IPFS gateway and associated hosting—remains accessible, posing a residual risk for redeployment. Users who interacted with the domain prior to takedown should assume credential exposure and initiate password resets for any accounts accessed during the period of activity. Organizations are advised to monitor for reuse of this IPFS content identifier (CID) or similar infrastructure across other gateways, as the decentralized nature of IPFS complicates complete mitigation.
Intelijen Keamanan Jaringan
Alur Tanggapan Ancaman Pipeline
Status Daftar Blokir Publik
Teknologi · 2 identified
Amazon Web Services (AWS) is a comprehensive cloud services platform offering compute power, database storage, content delivery and other functionality.
aws.amazon.com Keyakinan 100%AWS Certificate Manager is a service that lets you easily provision, manage, and deploy public and private Secure Sockets Layer/Transport Layer Security (SSL/TLS) certificates for use with AWS services and your internal connected resources.
aws.amazon.com Keyakinan 100%Analisis VirusTotal
Bukti & Laporan Eksternal
Apakah Anda Terpengaruh oleh Situs Ini?
Jika Anda memasukkan kredensial akun, informasi pribadi atau pembayaran, atau mengunduh file dari domain ini, segera ambil tindakan. Di bawah ini adalah sumber daya untuk membantu Anda melaporkan insiden tersebut dan melindungi diri Anda sendiri.
Laporkan kepada Pihak Berwenang di Daerah Anda
Pilih negara Anda untuk mendapatkan kontak resmi kejahatan dunia maya, atau membuat draf pengaduan →.
Periksa Domain Apa Pun
Analisis ancaman menggunakan daftar blokir yang disimpan, WHOIS, DNS, dan bukti pemindaian publik
Pindai SekarangLaporkan Phishing
Laporkan domain yang mencurigakan ke basis data ancaman kami — lindungi komunitas
LaporanPemberitahuan Ancaman Real-Time
Laporan phishing terbaru dan perubahan ketersediaan yang diamati
PantauTetap Terinformasi, Tetap Aman
Pantau ancaman secara langsung atau ajukan keberatan terhadap daftar ini jika Anda yakin ini merupakan false positive