bafybeids32ox432igs5e4nk6fc6juvvuj4tdossnwegpsq7sefoipipwve[.]ipfs[.]dweb[.]link
“410 Gone”
bafybeids32ox432igs5e4nk6fc6juvvuj4tdossnwegpsq7sefoipipwve.ipfs.dweb.link — Контент недоступний. Зведення доказів: VirusTotal 10/95 (alphaMountain.ai, BitDefender, CRDF, CyRadar, ESET); PhishDestroy score 80/100. Реєстратор: CSC.
Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.
The domain bafybeids32ox432igs5e4nk6fc6juvvuj4tdossnwegpsq7sefoipipwve.ipfs.dweb.link was observed as a generic phishing infrastructure and is currently offline as of the report date, July 24, 2026. Technical analysis shows the site was served through Cloudflare’s network, employing HTTP/3 and using the nameservers clarissa.ns.cloudflare.com and tate.ns.cloudflare.com. The TLS certificate was issued by Let’s Encrypt (E7), indicating a valid HTTPS endpoint at the time of capture. HTTP responses returned a 410 Gone status with the page title explicitly showing "410 Gone," confirming that the content has been removed or is no longer accessible.
The domain resolves to IP address 209.94.90.2, which belongs to AS40680 (Protocol Labs) and is geolocated in the United States. Registration records list CSC Corporate Domains, Inc. as the registrar, and the domain creation date is recorded as February 24, 2017. Threat intelligence indicates that the domain was flagged by ten of ninety‑five VirusTotal scanners, and it appears on a single security blocklist. It was also blocked by the PhishDestroy mitigation service, reinforcing its classification as a phishing host.
The elevated risk rating reflects the combination of its historical phishing use, the presence of multiple detection vendor alerts, and its association with Cloudflare infrastructure that can obscure attribution. Uncertainty remains regarding any active payload or credential‑stealing pages because the site now returns a 410 status, and no additional page content has been captured. Defenders should continue to block the domain at network perimeter devices, ensure that any cached DNS entries are purged, and monitor for re‑registration attempts. Ongoing vigilance is recommended for any future resolution of the IP address or reuse of the Cloudflare nameservers, as these could indicate a revival of the phishing operation.
Процес реагування на загрози Pipeline
Статус у публічних блоклистах
Збережений знімок
Аналітика доменів
Технічні деталіDNS, SAN-адреси SSL, мітки часу
Технології · 2 identified
Cloudflare is a web-infrastructure and website-security company, providing content-delivery-network services, DDoS mitigation, Internet security, and distributed domain-name-server services.
www.cloudflare.com 100% впевненостіHTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org 100% впевненостіАналіз VirusTotal
Архівні докази
Докази та зовнішні звіти
Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога