bafybeifn4q7vghs7f3xwilosxa4dyllaadejgevezprlqf5cgs5mgpvmr4[.]ipfs[.]dweb[.]link
“Vertex”
bafybeifn4q7vghs7f3xwilosxa4dyllaadejgevezprlqf5cgs5mgpvmr4.ipfs.dweb.link — Неперевірений. Зведення доказів: VirusTotal 11/91 (alphaMountain.ai, BitDefender, CyRadar, Emsisoft, G-Data); 1 external blocklist match (ScamSniffer); PhishDestroy score 88/100. Реєстратор: CSC.
Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.
This domain, hosted on the InterPlanetary File System (IPFS) gateway dweb.link, is currently flagged as an active generic phishing threat targeting users under the page title 'Vertex'. Infrastructure analysis reveals the domain resolves to the IP address 209.94.90.3, associated with AS40680 (Protocol Labs) in the United States. The domain was registered on February 24, 2017, through CSC Corporate Domains, Inc., and employs Cloudflare nameservers (clarissa.ns.cloudflare.com and tate.ns.cloudflare.com) alongside HTTP/3 support, indicating modern infrastructure designed to evade detection or blocking attempts. The SSL certificate is issued by Let's Encrypt (serial number E7), a common choice for both legitimate and malicious sites due to its free and automated nature. A 301 HTTP status code suggests the domain may redirect visitors to another location, though the final destination remains unconfirmed. Security vendor detections are minimal but notable: one of ninety-five vendors on VirusTotal has flagged the domain, while two independent blocklists (PhishDestroy and ScamSniffer) have explicitly blocked it. Scamadviser assigns a trust score of 1 out of 100, reinforcing the high-risk classification. The exact nature of the phishing content is not yet analysed, as no brand target or scam type is specified in available data. The page title 'Vertex' may refer to a legitimate entity, but without further evidence, this cannot be confirmed. Defenders should treat this domain as a generic phishing threat, particularly given its persistence since at least early 2026 and its use of IPFS, which complicates takedown efforts. Network-level blocking of the IP 209.94.90.3 and Cloudflare nameservers may mitigate exposure, though monitoring for redirects or evolving infrastructure is recommended. No cryptocurrency wallet addresses, payment gateways, or specific lures have been identified in the provided intelligence.
Сигнали безпеки
Процес реагування на загрози Pipeline
Статус у публічних блоклистах
Технології · 2 identified
Cloudflare is a web-infrastructure and website-security company, providing content-delivery-network services, DDoS mitigation, Internet security, and distributed domain-name-server services.
www.cloudflare.com 100% впевненостіHTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org 100% впевненостіАналіз VirusTotal
Архівні докази
Докази та зовнішні звіти
Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога