bafybeibdyr3vrviyiqdrraxyk5dxy5fb6subupjbgqwyvki3b7pn2h32lm[.]ipfs[.]w3s[.]link
“The Courier Guy”
bafybeibdyr3vrviyiqdrraxyk5dxy5fb6subupjbgqwyvki3b7pn2h32lm.ipfs.w3s.link — Doğrulanmamış. Marka kimliğine bürünme: Base; Dolandırıcılık türü: Crypto Scam. Kanıt özeti: VirusTotal 12/91 (alphaMountain.ai, Chong Lua Dao, Forcepoint ThreatSeeker, Fortinet, G-Data); URLScan malicious verdict; CF Radar malicious; PhishDestroy score 91/100. Kayıt kuruluşu: 1API.
Özgün adli kaydı korumak için aşağıdaki ayrıntılı PhishDestroy AI analizi İngilizce bırakılmıştır.
This domain, bafybeibdyr3vrviyiq.ipfs.w3s.link, is identified as a brand impersonation threat targeting Base, a Layer 2 blockchain network. Analysis of the infrastructure reveals the domain was designed to mimic legitimate Base-related services, likely to deceive users into engaging with fraudulent crypto transactions or credential submission. The page title, 'The Courier Guy,' does not align with Base’s branding, suggesting an attempt to obfuscate the true intent of the page or a misconfiguration in the phishing kit deployment. No direct evidence of a crypto drainer script was observed, but the domain’s structure and hosting method (IPFS via Cloudflare) are consistent with tactics used in cryptocurrency-related fraud campaigns. Technical indicators confirm the elevated risk associated with this domain. It is flagged by 21 out of 95 security vendors on VirusTotal, indicating broad detection across multiple threat intelligence platforms. The domain was registered through 1API GmbH on June 27, 2022, and resolves to the IPv6 address 2a06:98c1:3108::ac40:9257, hosted on Cloudflare’s infrastructure (AS13335). The SSL certificate is issued by Google Trust Services (WE1), a common feature in both legitimate and malicious domains to avoid immediate browser warnings. The domain appears on two security blocklists and is explicitly blocked by PhishDestroy and PhishingDB. Despite its creation date suggesting longevity, the domain’s association with brand impersonation and its detection history raise significant concerns. As of the latest assessment, the domain has been taken offline, likely due to enforcement actions by the hosting provider or domain registrar. However, the residual risk remains elevated due to the domain’s prior use in brand impersonation and its potential for re-emergence under similar infrastructure. Organizations and users are advised to monitor for related indicators of compromise, including the IPv6 address, registrar details, and SSL certificate issuer. Blocking the domain and its associated IP at the network level is recommended to prevent accidental access. Users should verify the authenticity of any Base-related communications or services by cross-referencing official channels and avoiding interaction with unsolicited links or pages.
Ağ Güvenliği İstihbaratı
Tehdit Müdahale Pipeline
Genel Engelleme Listesi Durumu
Kaydedilen görüntü
Etki Alanı Analizi
Teknik ayrıntılarDNS, SSL SAN’ları, zaman damgaları
ICANN OVERSIGHT
Registration: w3s.link
Akreditasyon ve RAA bağlamı
Akreditasyon ve RAA bağlamı
Registrar accreditation and DNS abuse obligations
For the registrable domain w3s.link behind this subdomain, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Teknolojiler · 2 identified
Tag management system for deploying marketing and analytics tags.
tagmanager.google.comWeb infrastructure and security company providing CDN, DDoS mitigation, and DNS services.
www.cloudflare.comVirusTotal Analizi
Arşivlenmiş Kanıtlar
Site Performans Analizi
Google PageSpeed Insights — mobile performance audit of bafybeibdyr3vrviyiqdrraxyk5dxy5fb6subupjbgqwyvki3b7pn2h32lm.ipfs.w3s.link · checked Mar 1, 2026
Kanıtlar ve Dış Raporlar
Bu Siteden Etkilendiniz mi?
Hesap kimlik bilgilerini, kişisel bilgileri veya ödeme bilgilerini girdiyseniz ya da bu alan adından bir dosya indirdiyseniz hemen harekete geçin. Aşağıda olayı bildirmenize ve kendinizi korumanıza yardımcı olacak kaynaklar bulunmaktadır.
Yerel Yetkililere Bildirin
resmi siber suç iletişim bilgileri veya şikayet taslağı oluştur → almak için ülkenizi seçin.
Herhangi Bir Alan Adını Kontrol Et
Saklanan engelleme listesi, WHOIS, DNS ve genel tarama kanıtlarını kullanarak tehdit analizi
Şimdi TaraOltalama Olayını Bildir
Şüpheli alan adlarını tehdit veritabanımıza bildirin — topluluğu koruyun
BildirCanlı Tehdit Akışı
Son kimlik avı raporları ve gözlemlenen kullanılabilirlik değişiklikleri
İzleGelişmelerden Haberdar Olun, Güvende Kalın
Canlı tehditleri izleyin veya bunun yanlış bir uyarı olduğunu düşünüyorsanız bu kayda itiraz edin