bafkreidsfteign6t345vr7fozvxb3jcg7h4rojn2c6kmvjrxpmgdsslx4e[.]ipfs[.]dweb[.]link
“Sign in - Professional Email”
bafkreidsfteign6t345vr7fozvxb3jcg7h4rojn2c6kmvjrxpmgdsslx4e.ipfs.dweb.link — 内容不可用. 品牌冒充:Networksolutions. 证据摘要: VirusTotal 21/93 (ADMINUSLabs, alphaMountain.ai, BitDefender, CRDF, CyRadar); URLQuery 3 alerts; URLScan malicious verdict; CF Radar malicious; PhishDestroy score 95/100. 注册商: CSC.
为保留原始取证记录,下方的 PhishDestroy AI 详细分析仍使用英文。
The domain bafkreidsfteign6t345vr7fozvxb3jcg7h4rojn2c6kmvjrxpmgdsslx4e.ipfs.dweb.link has been identified as a crypto drainer phishing threat. Analysis indicates the domain is currently offline, returning a 410 Gone HTTP status code. No specific brand impersonation was detected, but the infrastructure is designed to facilitate unauthorized cryptocurrency transactions by tricking users into connecting wallets or entering private keys. Infrastructure analysis reveals the domain resolves to the IP address 209.94.90.2, hosted under AS40680 (Protocol Labs) in the United States. The domain was registered on March 01, 2026, through CSC Corporate Domains, Inc., and is associated with a Let's Encrypt SSL certificate (serial number E7). Security vendors have flagged this domain as malicious, with 21 out of 95 VirusTotal engines detecting it as a threat. Additionally, the domain appears on one security blocklist, further corroborating its malicious nature. The page title, 410 Gone, suggests the domain may have been actively mitigated or abandoned following detection. Current status indicates the domain is offline, reducing immediate risk to users. However, the infrastructure remains a potential threat vector. Organizations and individuals are advised to block the domain and its associated IP (209.94.90.2) at the network level. Users should verify wallet connections and avoid interacting with unsolicited links, particularly those distributed via email or social media. Monitoring for similar domains registered through the same registrar or resolving to the same IP range is recommended to preemptively mitigate related threats. Cryptocurrency users should enable transaction simulation tools and multi-factor authentication for wallet access to minimize exposure to drainer attacks.
网络安全情报
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| OpenDNS | bafkreidsfteign6t345vr7fozvxb3jcg7h4rojn2c6kmvjrxpmgdsslx4e.ipfs.dweb.link |
phishing | Phishing Block |
| DNS4EU | bafkreidsfteign6t345vr7fozvxb3jcg7h4rojn2c6kmvjrxpmgdsslx4e.ipfs.dweb.link |
malicious | Sinkholed |
| Cloudflare DNS | bafkreidsfteign6t345vr7fozvxb3jcg7h4rojn2c6kmvjrxpmgdsslx4e.ipfs.dweb.link |
malicious | Sinkholed |
威胁响应 Pipeline
公共封禁名单状态
所用技术 · 2 identified
Cloudflare is a web-infrastructure and website-security company, providing content-delivery-network services, DDoS mitigation, Internet security, and distributed domain-name-server services.
www.cloudflare.com 置信度 100%HTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org 置信度 100%VirusTotal 分析
存档证据
网站性能分析
Google PageSpeed Insights — mobile performance audit of bafkreidsfteign6t345vr7fozvxb3jcg7h4rojn2c6kmvjrxpmgdsslx4e.ipfs.dweb.link · checked Mar 2, 2026
网站配置分析
证据与外部报告
您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。