bafkreia2wkoizc7t42gtd3e76kklkp545ze6hr4gf6pji7fznqo3hibqqm[.]ipfs[.]dweb[.]link
“EmailLogin”
bafkreia2wkoizc7t42gtd3e76kklkp545ze6hr4gf6pji7fznqo3hibqqm.ipfs.dweb.link — Непроверенный. Тип мошенничества: Credential Phishing. Сводка доказательств: VirusTotal 18/91 (ADMINUSLabs, alphaMountain.ai, BitDefender, Chong Lua Dao, CRDF); URLQuery 4 alerts; CF Radar malicious; PhishDestroy score 95/100. Регистратор: CSC.
Подробный анализ PhishDestroy AI ниже оставлен на английском, чтобы сохранить исходную криминалистическую запись.
This domain, bafkreia2wkoizc7t42gtd3e76kklkp545ze6hr4gf6pji7fznqo3hibqqm.ipfs.dweb.link, is flagged as a high-risk generic phishing threat targeting email credentials. Analysis indicates the domain was registered on April 26, 2026, and currently resolves to the IP address 209.94.90.2, hosted by Protocol Labs in the United States. The page title, EmailLogin, suggests an attempt to mimic legitimate email authentication portals, a common tactic in credential harvesting campaigns. Infrastructure analysis reveals the use of Cloudflare nameservers (clarissa.ns.cloudflare.com and tate.ns.cloudflare.com) and HTTP/3, which may be leveraged to obscure malicious traffic or evade detection. The domain is actively blocked by one security vendor and appears on a single blocklist, though VirusTotal reports 15 out of 95 security vendors flagging it as malicious. This discrepancy may reflect delayed detection or varying classification criteria among vendors. The SSL certificate issued by Let's Encrypt further complicates analysis, as legitimate certificates are frequently abused to lend credibility to phishing sites. While the domain's IPFS-based hosting via dweb.link is not inherently malicious, it provides threat actors with decentralized, resilient infrastructure that can be difficult to takedown. Defenders should prioritize blocking this domain at the DNS or network level, particularly in environments where email credential theft poses a significant risk. Monitoring for connections to 209.94.90.2 or requests to the domain's path may help identify compromised endpoints. Given the domain's active status and the presence of a plausible login interface, organizations should also assess whether any users have interacted with the site and initiate password resets or additional authentication measures if necessary. The use of Cloudflare and IPFS infrastructure suggests the threat actor may reuse this hosting setup for future campaigns, warranting broader scrutiny of similar domains.
Данные сетевой безопасности
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| OpenDNS | bafkreia2wkoizc7t42gtd3e76kklkp545ze6hr4gf6pji7fznqo3hibqqm.ipfs.dweb.link |
phishing | Phishing Block |
| DNS4EU | bafkreia2wkoizc7t42gtd3e76kklkp545ze6hr4gf6pji7fznqo3hibqqm.ipfs.dweb.link |
malicious | Sinkholed |
| Hagezi Threat Feed | www.kosherbh.com |
malicious | Sinkholed |
| DNS4EU | www.kosherbh.com |
malicious | Sinkholed |
Процесс реагирования на угрозы
Статус в публичных блок-листах
Сохранённый снимок
Аналитика доменов
Технические сведенияDNS, SAN в протоколе SSL, временные метки
Технологии · 3 identified
IPFS is a peer-to-peer hypermedia protocol that provides a distributed hypermedia web.
ipfs.tech 100% уверенностиCloudflare is a web-infrastructure and website-security company, providing content-delivery-network services, DDoS mitigation, Internet security, and distributed domain-name-server services.
www.cloudflare.com 100% уверенностиHTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org 100% уверенностиАнализ VirusTotal
Анализ производительности сайта
Google PageSpeed Insights — mobile performance audit of bafkreia2wkoizc7t42gtd3e76kklkp545ze6hr4gf6pji7fznqo3hibqqm.ipfs.dweb.link · checked Apr 29, 2026
Анализ конфигурации сайта
Доказательства и внешние отчеты
Повлиял ли на вас этот сайт?
Если вы ввели учетные данные, личную или платежную информацию или загрузили файл с этого домена, примите немедленные меры. Ниже приведены ресурсы, которые помогут вам сообщить об инциденте и защитить себя.
Сообщите об этом в местные органы власти
Выберите свою страну, чтобы получить официальные контакты по киберпреступности или создать проект жалобы →.
Проверить любой домен
Анализ угроз с использованием сохраненного черного списка, WHOIS, DNS и общедоступных доказательств сканирования.
Сканировать сейчасСообщить о фишинге
Добавляйте подозрительные домены в нашу базу данных угроз — защищайте сообщество
СообщитьПоток оперативных данных об угрозах
Недавние сообщения о фишинге и наблюдаемые изменения доступности
ОтслеживатьБудьте в курсе событий, берегите себя
Отслеживайте актуальные угрозы или оспорьте эту запись, если считаете, что это ложное срабатывание