bafkreibupiq2fnvqdhui556opdnhkidbtrdapw46ytd5eis7vqfotuc72y[.]ipfs[.]dweb[.]link
“Webmail Sign-in”
bafkreibupiq2fnvqdhui556opdnhkidbtrdapw46ytd5eis7vqfotuc72y.ipfs.dweb.link — Doğrulanmamış. Marka kimliğine bürünme: Genericemail; Dolandırıcılık türü: Credential Phishing. Kanıt özeti: VirusTotal 16/91 (ADMINUSLabs, alphaMountain.ai, BitDefender, Chong Lua Dao, ESET); URLQuery 4 alerts; URLScan malicious verdict; CF Radar malicious; PhishDestroy score 100/100. Kayıt kuruluşu: CSC.
Özgün adli kaydı korumak için aşağıdaki ayrıntılı PhishDestroy AI analizi İngilizce bırakılmıştır.
This domain represents a credential-harvesting phishing operation specifically targeting webmail authentication portals. Analysis of the infrastructure reveals a fraudulent Webmail Sign-in page designed to capture user credentials through social engineering tactics. The threat actor appears focused on email account compromise, which could enable subsequent business email compromise attacks, data exfiltration, or lateral movement within organizational networks. Infrastructure analysis provides concrete evidence of malicious intent. The domain was registered through CSC Corporate Domains, Inc. on March 03, 2026, with detection metrics showing 20 out of 95 security vendors flagging the domain on VirusTotal. The domain appears on two independent security blocklists, indicating cross-industry recognition of the threat. Technical indicators include resolution to IP address 209.94.90.3 (AS40680 Protocol Labs) and use of Let's Encrypt E7 SSL certificate, suggesting attempts to appear legitimate while maintaining operational security. Users who visited this domain should immediately take corrective action. Any credentials entered on the Webmail Sign-in page should be considered compromised and changed from a separate, secure device. Organizations should review authentication logs for the affected accounts, particularly looking for anomalous login attempts or geographic inconsistencies. The domain's current offline status does not eliminate risk, as harvested credentials may be stored for future exploitation. Security teams should add the IP address 209.94.90.3 and associated domain patterns to monitoring systems for internal detection capabilities.
Ağ Güvenliği İstihbaratı
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| YARAhub by abuse.ch | bafkreibupiq2fnvqdhui556opdnhkidbtrdapw46ytd5eis7vqfotuc72y.ipfs.dweb.link/ |
malware | Detects file containing Telegram Bot API |
| DNS4EU | bafkreibupiq2fnvqdhui556opdnhkidbtrdapw46ytd5eis7vqfotuc72y.ipfs.dweb.link |
malicious | Sinkholed |
| OpenDNS | bafkreibupiq2fnvqdhui556opdnhkidbtrdapw46ytd5eis7vqfotuc72y.ipfs.dweb.link |
phishing | Phishing Block |
| Cloudflare DNS | bafkreibupiq2fnvqdhui556opdnhkidbtrdapw46ytd5eis7vqfotuc72y.ipfs.dweb.link |
malicious | Sinkholed |
Tehdit Müdahale Pipeline
Genel Engelleme Listesi Durumu
Teknolojiler · 5 identified
Popular CSS framework for responsive, mobile-first web development.
Free public CDN for open-source projects, serving files from npm and GitHub.
Web infrastructure and security company providing CDN, DDoS mitigation, and DNS services.
www.cloudflare.comThird major version of HTTP protocol, built on QUIC for faster, more reliable connections.
VirusTotal Analizi
Arşivlenmiş Kanıtlar
Site Performans Analizi
Google PageSpeed Insights — mobile performance audit of bafkreibupiq2fnvqdhui556opdnhkidbtrdapw46ytd5eis7vqfotuc72y.ipfs.dweb.link · checked Mar 6, 2026
Kanıtlar ve Dış Raporlar
Bu Siteden Etkilendiniz mi?
Hesap kimlik bilgilerini, kişisel bilgileri veya ödeme bilgilerini girdiyseniz ya da bu alan adından bir dosya indirdiyseniz hemen harekete geçin. Aşağıda olayı bildirmenize ve kendinizi korumanıza yardımcı olacak kaynaklar bulunmaktadır.
Yerel Yetkililere Bildirin
resmi siber suç iletişim bilgileri veya şikayet taslağı oluştur → almak için ülkenizi seçin.
Herhangi Bir Alan Adını Kontrol Et
Saklanan engelleme listesi, WHOIS, DNS ve genel tarama kanıtlarını kullanarak tehdit analizi
Şimdi TaraOltalama Olayını Bildir
Şüpheli alan adlarını tehdit veritabanımıza bildirin — topluluğu koruyun
BildirCanlı Tehdit Akışı
Son kimlik avı raporları ve gözlemlenen kullanılabilirlik değişiklikleri
İzleGelişmelerden Haberdar Olun, Güvende Kalın
Canlı tehditleri izleyin veya bunun yanlış bir uyarı olduğunu düşünüyorsanız bu kayda itiraz edin