bafkreicyghdtqspqrperjhwyfum7blmddcsnbeegsm5n46dfjkgypjcste[.]ipfs[.]dweb[.]link
“EmailLogin”
bafkreicyghdtqspqrperjhwyfum7blmddcsnbeegsm5n46dfjkgypjcste.ipfs.dweb.link — 未验证. 诈骗类型:Credential Phishing. 证据摘要: VirusTotal 19/91 (ADMINUSLabs, alphaMountain.ai, BitDefender, Chong Lua Dao, CRDF); URLQuery 5 alerts; PhishDestroy score 95/100. 注册商: CSC.
为保留原始取证记录,下方的 PhishDestroy AI 详细分析仍使用英文。
The domain bafkreicyghdtqspqrperjhwyfum7blmddcsnbeegsm5n46dfjkgypjcste.ipfs.dweb.link resolves to IP 209.94.90.2, an address registered to a US entity associated with Protocol Labs. The site presents a page titled "EmailLogin" and serves content over HTTPS using a Let’s Encrypt certificate (E8). Registration data shows the domain was created on February 24 2017 through CSC Corporate Domains, Inc. Security telemetry indicates the domain is currently active and has been flagged by 20 of 91 vendors on VirusTotal, while Gridinsoft assigns a trust score of 0 / 100. It is listed on one public blocklist and has been blocked by the PhishDestroy filtering service. The observed characteristics align with a credential‑phishing campaign targeting email credentials. Uncertainty remains around the specific phishing kit or any downstream infrastructure, as no additional indicators such as payload hashes or related command‑and‑control hosts have been disclosed. Defenders should prioritize blocking the domain and its resolved IP at perimeter and endpoint layers, enforce strict URL filtering for the ipfs.dweb.link suffix, and monitor TLS certificate changes for the Let’s Encrypt issuance. Continuous threat‑intel feeds should be consulted for any new detections linked to this IP or associated registrant, and incident response teams should be prepared to investigate credential‑theft attempts that reference the "EmailLogin" page title.
网络安全情报
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| OpenDNS | bafkreicyghdtqspqrperjhwyfum7blmddcsnbeegsm5n46dfjkgypjcste.ipfs.inbrowser.link |
phishing | Phishing Block |
| DNS4EU | bafkreicyghdtqspqrperjhwyfum7blmddcsnbeegsm5n46dfjkgypjcste.ipfs.inbrowser.link |
malicious | Sinkholed |
| Cloudflare DNS | bafkreicyghdtqspqrperjhwyfum7blmddcsnbeegsm5n46dfjkgypjcste.ipfs.dweb.link |
malicious | Sinkholed |
| OpenDNS | bafkreicyghdtqspqrperjhwyfum7blmddcsnbeegsm5n46dfjkgypjcste.ipfs.dweb.link |
phishing | Phishing Block |
| DNS4EU | bafkreicyghdtqspqrperjhwyfum7blmddcsnbeegsm5n46dfjkgypjcste.ipfs.dweb.link |
malicious | Sinkholed |
威胁响应 Pipeline
公共封禁名单状态
已保存的截图
域名情报
技术细节DNS、SSL SAN、时间戳
VirusTotal 分析
证据与外部报告
您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。