bafkreia2wkoizc7t42gtd3e76kklkp545ze6hr4gf6pji7fznqo3hibqqm[.]ipfs[.]dweb[.]link
“EmailLogin”
bafkreia2wkoizc7t42gtd3e76kklkp545ze6hr4gf6pji7fznqo3hibqqm.ipfs.dweb.link — 확인되지 않음. 사기 유형: Credential Phishing. 증거 요약: VirusTotal 18/91 (ADMINUSLabs, alphaMountain.ai, BitDefender, Chong Lua Dao, CRDF); URLQuery 4 alerts; CF Radar malicious; PhishDestroy score 95/100. 등록기관: CSC.
원본 포렌식 기록을 보존하기 위해 아래의 상세 PhishDestroy AI 분석은 영어로 유지됩니다.
This domain, bafkreia2wkoizc7t42gtd3e76kklkp545ze6hr4gf6pji7fznqo3hibqqm.ipfs.dweb.link, is flagged as a high-risk generic phishing threat targeting email credentials. Analysis indicates the domain was registered on April 26, 2026, and currently resolves to the IP address 209.94.90.2, hosted by Protocol Labs in the United States. The page title, EmailLogin, suggests an attempt to mimic legitimate email authentication portals, a common tactic in credential harvesting campaigns. Infrastructure analysis reveals the use of Cloudflare nameservers (clarissa.ns.cloudflare.com and tate.ns.cloudflare.com) and HTTP/3, which may be leveraged to obscure malicious traffic or evade detection. The domain is actively blocked by one security vendor and appears on a single blocklist, though VirusTotal reports 15 out of 95 security vendors flagging it as malicious. This discrepancy may reflect delayed detection or varying classification criteria among vendors. The SSL certificate issued by Let's Encrypt further complicates analysis, as legitimate certificates are frequently abused to lend credibility to phishing sites. While the domain's IPFS-based hosting via dweb.link is not inherently malicious, it provides threat actors with decentralized, resilient infrastructure that can be difficult to takedown. Defenders should prioritize blocking this domain at the DNS or network level, particularly in environments where email credential theft poses a significant risk. Monitoring for connections to 209.94.90.2 or requests to the domain's path may help identify compromised endpoints. Given the domain's active status and the presence of a plausible login interface, organizations should also assess whether any users have interacted with the site and initiate password resets or additional authentication measures if necessary. The use of Cloudflare and IPFS infrastructure suggests the threat actor may reuse this hosting setup for future campaigns, warranting broader scrutiny of similar domains.
네트워크 보안 인텔리전스
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| OpenDNS | bafkreia2wkoizc7t42gtd3e76kklkp545ze6hr4gf6pji7fznqo3hibqqm.ipfs.dweb.link |
phishing | Phishing Block |
| DNS4EU | bafkreia2wkoizc7t42gtd3e76kklkp545ze6hr4gf6pji7fznqo3hibqqm.ipfs.dweb.link |
malicious | Sinkholed |
| Hagezi Threat Feed | www.kosherbh.com |
malicious | Sinkholed |
| DNS4EU | www.kosherbh.com |
malicious | Sinkholed |
위협 대응 Pipeline
공개 차단 목록 상태
저장된 캡처
도메인 인텔리전스
기술적 세부 사항DNS, SSL SAN, 타임스탬프
사용 기술 · 3 identified
IPFS is a peer-to-peer hypermedia protocol that provides a distributed hypermedia web.
ipfs.tech 신뢰도 100%Cloudflare is a web-infrastructure and website-security company, providing content-delivery-network services, DDoS mitigation, Internet security, and distributed domain-name-server services.
www.cloudflare.com 신뢰도 100%HTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org 신뢰도 100%VirusTotal 분석
사이트 성능 분석
Google PageSpeed Insights — mobile performance audit of bafkreia2wkoizc7t42gtd3e76kklkp545ze6hr4gf6pji7fznqo3hibqqm.ipfs.dweb.link · checked Apr 29, 2026
사이트 구성 분석
증거 및 외부 보고서
이 사이트로 인해 영향을 받으셨나요?
계정 자격 증명, 개인 정보 또는 결제 정보를 입력했거나 이 도메인에서 파일을 다운로드한 경우 즉시 조치를 취하세요. 다음은 사건을 신고하고 자신을 보호하는 데 도움이 되는 리소스입니다.
지역 당국에 신고하십시오
공식 사이버 범죄 연락처 또는 불만사항 초안 작성 →를 받으려면 국가를 선택하세요.