bafybeigdc66io3yev7awofrteoyay6ghsx2jzqebhsim4sza26bvwm7ytq[.]ipfs[.]dweb[.]link
“CARV - Modular Data Layer for Gaming and AI”
bafybeigdc66io3yev7awofrteoyay6ghsx2jzqebhsim4sza26bvwm7ytq.ipfs.dweb.link — Неперевірений. Уособлення бренду: Revolut; Тип шахрайства: Impersonation. Зведення доказів: VirusTotal 13/91 (alphaMountain.ai, BitDefender, ESET, Emsisoft, G-Data); 1 external blocklist match (ScamSniffer); CF Radar malicious; PhishDestroy score 94/100. Реєстратор: CSC.
Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.
This domain, bafybeigdc66io3yev7awofrteoyay6ghsx2jzqebhsim4sza26bvwm7ytq.ipfs.dweb.link, is flagged as an active high-risk brand impersonation threat targeting Revolut. Infrastructure analysis reveals the domain is hosted on IPFS and resolves to 2602:fea2:2::2, with Cloudflare nameservers (clarissa.ns.cloudflare.com, tate.ns.cloudflare.com) and a Let's Encrypt SSL certificate. The domain was created on February 24, 2017, and is registered through CSC Corporate Domains, Inc. Despite its age, it currently serves a page titled 'CARV - Modular Data Layer for Gaming and AI,' which does not align with the targeted brand, suggesting either misdirection or a compromised legitimate resource repurposed for phishing. Security vendors flag this domain, with 10 out of 95 detections on VirusTotal, and it appears on two security blocklists (PhishDestroy, ScamSniffer). The HTTP 301 redirect indicates potential redirection to another malicious endpoint, though the final destination remains unconfirmed. Technologies detected include IPFS, Google Tag Manager, Cloudflare, and HTTP/3, which may be leveraged to evade detection or track victims. Defenders should treat this domain as active and high-risk. Immediate actions include blocking resolution at the DNS level, monitoring for connections to the associated IP (2602:fea2:2::2), and investigating any internal access attempts. The discrepancy between the page title and the impersonated brand warrants further analysis to determine if this is a phishing kit, a compromised IPFS resource, or part of a broader campaign. Given the domain's age and infrastructure, retrospective log analysis may identify prior compromise activity.
Сигнали безпеки
Розвіддані з мережевої безпеки
Процес реагування на загрози Pipeline
Статус у публічних блоклистах
Технології · 4 identified
IPFS is a peer-to-peer hypermedia protocol that provides a distributed hypermedia web.
ipfs.tech 100% впевненостіGoogle Tag Manager is a tag management system (TMS) that allows you to quickly and easily update measurement codes and related code fragments collectively known as tags on your website or mobile app.
www.google.com 100% впевненостіCloudflare is a web-infrastructure and website-security company, providing content-delivery-network services, DDoS mitigation, Internet security, and distributed domain-name-server services.
www.cloudflare.com 100% впевненостіHTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org 100% впевненостіАналіз VirusTotal
Архівні докази
Аналіз конфігурації сайту
Докази та зовнішні звіти
Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога