bafkreihozxz6uz57gmezial5t3ysbxi2zyanve27ndf23dtmljw2zg5qga[.]ipfs[.]dweb[.]link
“Rackspace Webmail: Hosted Email for Business”
bafkreihozxz6uz57gmezial5t3ysbxi2zyanve27ndf23dtmljw2zg5qga.ipfs.dweb.link — İçerik kullanılamıyor. Marka kimliğine bürünme: Rackspace; Dolandırıcılık türü: Brand Impersonation. Kanıt özeti: VirusTotal 19/93 (ADMINUSLabs, alphaMountain.ai, BitDefender, CRDF, CyRadar); URLScan malicious verdict; CF Radar malicious; PhishDestroy score 95/100. Kayıt kuruluşu: CSC.
Özgün adli kaydı korumak için aşağıdaki ayrıntılı PhishDestroy AI analizi İngilizce bırakılmıştır.
This domain, bafkreihozxz6uz5.ipfs.dweb.link, represents a targeted brand impersonation threat designed to harvest enterprise credentials by mimicking Rackspace Webmail services. Analysis indicates the infrastructure presents a fraudulent login portal titled 'Rackspace Webmail: Hosted Email for Business,' a direct replication of the legitimate Rackspace webmail interface. The intent is to deceive employees or customers into submitting corporate email credentials, enabling subsequent unauthorized access to internal communications, sensitive data, or further lateral movement within compromised networks. Credential theft of this nature often serves as an initial access vector for business email compromise, data exfiltration, or ransomware deployment, particularly in enterprise environments where cloud-based email services are widely adopted. Infrastructure analysis reveals multiple high-confidence indicators supporting the malicious classification of this domain. The resource is hosted on IP address 209.94.90.3, originating from AS40680 (Protocol Labs) in the United States, and uses a Let's Encrypt SSL certificate (identifier E7) to lend an appearance of legitimacy. The domain was registered through CSC Corporate Domains, Inc. on February 21, 2026, though the creation date appears anomalous and may reflect backdating or administrative manipulation. Security telemetry shows the domain is flagged by 19 out of 95 security vendors on VirusTotal, with additional presence on one active blocklist. The combination of brand impersonation, anomalous registration data, and multi-source detection strongly suggests orchestrated malicious activity rather than benign misconfiguration. Users who accessed or entered credentials on bafkreihozxz6uz5.ipfs.dweb.link should immediately take corrective action to mitigate potential compromise. All submitted credentials must be considered exposed and should be reset across all associated accounts, particularly corporate email and single sign-on systems. Enable multi-factor authentication where available, and monitor affected accounts for unauthorized access or anomalous activity such as unexpected password reset emails, login attempts from unfamiliar locations, or suspicious email forwarding rules. Organizations should review logs for connections to 209.94.90.3 and the domain in question, and consider isolating any endpoints that interacted with the resource. Given the elevated risk profile, affected users are advised to conduct a full security review of their email environment and report the incident to internal security teams or relevant incident response authorities.
Ağ Güvenliği İstihbaratı
Tehdit Müdahale Pipeline
Genel Engelleme Listesi Durumu
Teknolojiler · 2 identified
Web infrastructure and security company providing CDN, DDoS mitigation, and DNS services.
www.cloudflare.comThird major version of HTTP protocol, built on QUIC for faster, more reliable connections.
VirusTotal Analizi
Arşivlenmiş Kanıtlar
Kanıtlar ve Dış Raporlar
Bu Siteden Etkilendiniz mi?
Hesap kimlik bilgilerini, kişisel bilgileri veya ödeme bilgilerini girdiyseniz ya da bu alan adından bir dosya indirdiyseniz hemen harekete geçin. Aşağıda olayı bildirmenize ve kendinizi korumanıza yardımcı olacak kaynaklar bulunmaktadır.
Yerel Yetkililere Bildirin
resmi siber suç iletişim bilgileri veya şikayet taslağı oluştur → almak için ülkenizi seçin.
Herhangi Bir Alan Adını Kontrol Et
Saklanan engelleme listesi, WHOIS, DNS ve genel tarama kanıtlarını kullanarak tehdit analizi
Şimdi TaraOltalama Olayını Bildir
Şüpheli alan adlarını tehdit veritabanımıza bildirin — topluluğu koruyun
BildirCanlı Tehdit Akışı
Son kimlik avı raporları ve gözlemlenen kullanılabilirlik değişiklikleri
İzleGelişmelerden Haberdar Olun, Güvende Kalın
Canlı tehditleri izleyin veya bunun yanlış bir uyarı olduğunu düşünüyorsanız bu kayda itiraz edin