bafkreictgoqh23cwflhs54whbr4qfmydt6b37wkeai4mie7vdq3tcistxe[.]ipfs[.]dweb[.]link
“Webmail Sign-in”
bafkreictgoqh23cwflhs54whbr4qfmydt6b37wkeai4mie7vdq3tcistxe.ipfs.dweb.link — Contenuto non disponibile. Simulazione del marchio: Genericemail; Tipo di truffa: Credential Phishing. Riepilogo delle prove: VirusTotal 22/94 (ADMINUSLabs, alphaMountain.ai, BitDefender, Chong Lua Dao, CRDF); URLQuery 4 alerts; URLScan malicious verdict; CF Radar malicious; PhishDestroy score 100/100. Registrar: CSC.
L’analisi dettagliata di PhishDestroy AI resta in inglese per preservare il rapporto forense originale.
PhishDestroy identifies an active generic phishing threat associated with the domain bafkreictgoqh23cwflhs54whbr4qfmydt6b37wkeai4mie7vdq3tcistxe.ipfs.dweb.link. This entry has been assigned an elevated risk rating due to confirmed malicious behavior and widespread detection across multiple security platforms. The domain leverages IPFS hosting infrastructure to distribute phishing lures, often mimicking legitimate login portals or financial services to harvest user credentials and sensitive data. Security analysts confirm this domain resolves to a high-risk IP address (209.94.90.2), which has been linked to prior phishing campaigns and botnet activity. The presence of a valid Let’s Encrypt SSL certificate increases the appearance of legitimacy, deceiving users into trusting the site. With a seed identifier of e5edb5, this domain represents a persistent and evolving threat vector within decentralized web environments. This domain was flagged by 18 out of 95 VirusTotal security vendors, indicating strong consensus among antivirus and threat intelligence platforms about its malicious intent. Registered through CSC Corporate Domains, Inc. on February 24, 2017, this long-standing domain has been repurposed to host phishing content, demonstrating the tactic of leveraging aged domains for credibility. The domain’s integration with IPFS (InterPlanetary File System) further complicates takedown efforts and enables circumvention of traditional web filtering mechanisms. Given its prolonged existence and current active status, this domain has likely been involved in multiple phishing operations targeting unsuspecting users across various sectors. Users who have accessed this domain or encountered it in emails, ads, or social media should immediately cease any interaction and avoid entering credentials or personal information. It is strongly recommended to scan all connected devices with updated antivirus and anti-malware software to detect potential infections or data exfiltration. Users are also advised to change passwords for any accounts that may have been accessed after visiting this domain, especially if credentials were entered on a page hosted at this location. Report the domain to your organization’s security team or to platforms such as Google Safe Browsing, PhishTank, or the Anti-Phishing Working Group to help disrupt ongoing campaigns. Exercise heightened caution with links or attachments from unknown or unsolicited sources, and enable multi-factor authentication wherever possible to mitigate the risk of credential theft.
Informazioni sulla sicurezza di rete
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| YARAhub by abuse.ch | bafkreictgoqh23cwflhs54whbr4qfmydt6b37wkeai4mie7vdq3tcistxe.ipfs.dweb.link/ |
malware | Detects file containing Telegram Bot API |
| DNS4EU | bafkreictgoqh23cwflhs54whbr4qfmydt6b37wkeai4mie7vdq3tcistxe.ipfs.dweb.link |
malicious | Sinkholed |
| Cloudflare DNS | bafkreictgoqh23cwflhs54whbr4qfmydt6b37wkeai4mie7vdq3tcistxe.ipfs.dweb.link |
malicious | Sinkholed |
| OpenDNS | bafkreictgoqh23cwflhs54whbr4qfmydt6b37wkeai4mie7vdq3tcistxe.ipfs.dweb.link |
phishing | Phishing Block |
Pipeline di risposta alle minacce
Stato della lista di blocco pubblica
Tecnologie · 5 identified
Popular CSS framework for responsive, mobile-first web development.
Free public CDN for open-source projects, serving files from npm and GitHub.
Web infrastructure and security company providing CDN, DDoS mitigation, and DNS services.
www.cloudflare.comThird major version of HTTP protocol, built on QUIC for faster, more reliable connections.
Analisi di VirusTotal
Analisi delle prestazioni del sito
Google PageSpeed Insights — mobile performance audit of bafkreictgoqh23cwflhs54whbr4qfmydt6b37wkeai4mie7vdq3tcistxe.ipfs.dweb.link · checked Mar 29, 2026
Dati e relazioni esterne
Questo sito ti ha influenzato in qualche modo?
Se hai inserito credenziali dell'account, informazioni personali o di pagamento oppure hai scaricato un file da questo dominio, agisci immediatamente. Di seguito sono riportate le risorse per aiutarti a segnalare l'incidente e proteggerti.
Segnalalo alle autorità locali
Seleziona il tuo Paese per ottenere contatti ufficiali del crimine informatico o creare una bozza di reclamo →.
Verifica qualsiasi dominio
Analisi delle minacce utilizzando blocklist archiviate, WHOIS, DNS e prove di scansione pubblica
Scansiona oraSegnala un tentativo di phishing
Segnala i domini sospetti al nostro database delle minacce — proteggi la comunità
SegnalaFeed in tempo reale sulle minacce
Segnalazioni recenti di phishing e modifiche osservate della disponibilità
MonitoraRimani informato, rimani al sicuro
Controlla le minacce in tempo reale oppure contesta questa segnalazione se ritieni che si tratti di un falso positivo