bafkreihozxz6uz57gmezial5t3ysbxi2zyanve27ndf23dtmljw2zg5qga[.]ipfs[.]dweb[.]link
“Rackspace Webmail: Hosted Email for Business”
bafkreihozxz6uz57gmezial5t3ysbxi2zyanve27ndf23dtmljw2zg5qga.ipfs.dweb.link — 콘텐츠를 사용할 수 없음. 브랜드 사칭: Rackspace; 사기 유형: Brand Impersonation. 증거 요약: VirusTotal 19/93 (ADMINUSLabs, alphaMountain.ai, BitDefender, CRDF, CyRadar); URLScan malicious verdict; CF Radar malicious; PhishDestroy score 95/100. 등록기관: CSC.
원본 포렌식 기록을 보존하기 위해 아래의 상세 PhishDestroy AI 분석은 영어로 유지됩니다.
This domain, bafkreihozxz6uz5.ipfs.dweb.link, represents a targeted brand impersonation threat designed to harvest enterprise credentials by mimicking Rackspace Webmail services. Analysis indicates the infrastructure presents a fraudulent login portal titled 'Rackspace Webmail: Hosted Email for Business,' a direct replication of the legitimate Rackspace webmail interface. The intent is to deceive employees or customers into submitting corporate email credentials, enabling subsequent unauthorized access to internal communications, sensitive data, or further lateral movement within compromised networks. Credential theft of this nature often serves as an initial access vector for business email compromise, data exfiltration, or ransomware deployment, particularly in enterprise environments where cloud-based email services are widely adopted. Infrastructure analysis reveals multiple high-confidence indicators supporting the malicious classification of this domain. The resource is hosted on IP address 209.94.90.3, originating from AS40680 (Protocol Labs) in the United States, and uses a Let's Encrypt SSL certificate (identifier E7) to lend an appearance of legitimacy. The domain was registered through CSC Corporate Domains, Inc. on February 21, 2026, though the creation date appears anomalous and may reflect backdating or administrative manipulation. Security telemetry shows the domain is flagged by 19 out of 95 security vendors on VirusTotal, with additional presence on one active blocklist. The combination of brand impersonation, anomalous registration data, and multi-source detection strongly suggests orchestrated malicious activity rather than benign misconfiguration. Users who accessed or entered credentials on bafkreihozxz6uz5.ipfs.dweb.link should immediately take corrective action to mitigate potential compromise. All submitted credentials must be considered exposed and should be reset across all associated accounts, particularly corporate email and single sign-on systems. Enable multi-factor authentication where available, and monitor affected accounts for unauthorized access or anomalous activity such as unexpected password reset emails, login attempts from unfamiliar locations, or suspicious email forwarding rules. Organizations should review logs for connections to 209.94.90.3 and the domain in question, and consider isolating any endpoints that interacted with the resource. Given the elevated risk profile, affected users are advised to conduct a full security review of their email environment and report the incident to internal security teams or relevant incident response authorities.
네트워크 보안 인텔리전스
위협 대응 Pipeline
공개 차단 목록 상태
사용 기술 · 2 identified
Web infrastructure and security company providing CDN, DDoS mitigation, and DNS services.
www.cloudflare.comThird major version of HTTP protocol, built on QUIC for faster, more reliable connections.
VirusTotal 분석
보관된 증거
증거 및 외부 보고서
이 사이트로 인해 영향을 받으셨나요?
계정 자격 증명, 개인 정보 또는 결제 정보를 입력했거나 이 도메인에서 파일을 다운로드한 경우 즉시 조치를 취하세요. 다음은 사건을 신고하고 자신을 보호하는 데 도움이 되는 리소스입니다.
지역 당국에 신고하십시오
공식 사이버 범죄 연락처 또는 불만사항 초안 작성 →를 받으려면 국가를 선택하세요.