bafybeidqp2rvj7tisdarxknqei2iskr4uwtzyrfsghgcdovn3g33i5fube[.]ipfs[.]dweb[.]link
“Orbiter”
bafybeidqp2rvj7tisdarxknqei2iskr4uwtzyrfsghgcdovn3g33i5fube.ipfs.dweb.link — Não verificado. Resumo das evidências: VirusTotal 12/91 (alphaMountain.ai, BitDefender, Chong Lua Dao, CyRadar, Emsisoft); 1 external blocklist match (ScamSniffer); PhishDestroy score 88/100. Registrador: CSC.
A análise detalhada do PhishDestroy AI permanece em inglês para preservar o registro forense original.
The domain bafybeidqp2rvj7tisdarxknqei2iskr4uwtz... is hosted on an IP address (209.94.90.3) that resolves to a United States location associated with ASN 40680, operated by Protocol Labs. The site presents a valid SSL certificate issued by Let’s Encrypt (E7) and returns an HTTP 301 redirect, indicating an active web service. Infrastructure analysis shows the domain is delegated to Cloudflare nameservers (clarissa.ns.cloudflare.com and tate.ns.cloudflare.com) and leverages HTTP/3, reflecting modern delivery mechanisms. Registration data indicates the domain was created on February 24, 2017 through CSC Corporate Domains, Inc., and the page title observed is "Orbiter". The domain appears on two independent security blocklists, PhishDestroy and ScamSniffer, confirming that external threat‑intel sources have identified it as a malicious resource.
Current intelligence classifies the domain as a generic phishing threat and places its risk level as under investigation. The presence on multiple blocklists, combined with the use of a reputable certificate authority and Cloudflare’s CDN, suggests an attempt to increase credibility and evade simple detection. However, the specific phishing campaign details, such as targeted brands or the nature of the harvested credentials, remain unknown because no additional content analysis has been performed. The lack of detections on VirusTotal does not imply safety; it merely reflects that automated scanners have not yet flagged the payload.
Defenders should prioritize monitoring network traffic to the IP 209.94.90.3 and enforce strict outbound filtering for HTTP/3 connections to this address. Blocking the domain at the DNS layer, especially by adding it to internal blocklists, will prevent user access. Continuous re‑evaluation of the domain’s activity is recommended, as its status is marked active and under investigation, and further indicators may emerge as threat actors evolve the campaign.
Pipeline de resposta a ameaças
Status da lista de bloqueios pública
Tecnologias · 2 identified
Cloudflare is a web-infrastructure and website-security company, providing content-delivery-network services, DDoS mitigation, Internet security, and distributed domain-name-server services.
www.cloudflare.com 100% de confiançaHTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org 100% de confiançaAnálise do VirusTotal
Evidências arquivadas
Evidências e relatórios externos
Você foi afetado por este site?
Se você inseriu credenciais de conta, informações pessoais ou de pagamento, ou baixou um arquivo deste domínio, tome medidas imediatas. Abaixo estão os recursos para ajudá-lo a relatar o incidente e se proteger.
Notifique as autoridades locais
Selecione seu país para obter contactos oficiais do cibercrime ou crie um rascunho de reclamação →.
Verificar qualquer domínio
Análise de ameaças usando lista de bloqueio armazenada, WHOIS, DNS e evidências de verificação pública
Digitalize agoraDenunciar phishing
Envie domínios suspeitos para nosso banco de dados de ameaças — proteja a comunidade
DenunciarFeed de ameaças em tempo real
Relatórios recentes de phishing e alterações de disponibilidade observadas
MonitorarMantenha-se informado, mantenha-se seguro
Monitore ameaças em tempo real ou conteste esta listagem caso acredite que se trate de um falso positivo