bafkreigitj7uo2ip62qmnl6n4tf4ammrx3kiqxl7zz7sdqy66pc7yemygi[.]ipfs[.]dweb[.]link
“EmailLogin”
bafkreigitj7uo2ip62qmnl6n4tf4ammrx3kiqxl7zz7sdqy66pc7yemygi.ipfs.dweb.link — 内容不可用. 诈骗类型:Credential Phishing. 证据摘要: VirusTotal 17/94 (ADMINUSLabs, alphaMountain.ai, Chong Lua Dao, CRDF, CyRadar); URLQuery 4 alerts; PhishDestroy score 100/100. 注册商: CSC.
为保留原始取证记录,下方的 PhishDestroy AI 详细分析仍使用英文。
PhishDestroy identifies an active crypto drainer domain hosted via IPFS at bafkreigitj7uo2ip62qmnl6n4tf4ammrx3kiqxl7zz7sdqy66pc7yemygi.ipfs.dweb.link. The site was flagged under a generic phishing threat vector, specifically designed to intercept cryptocurrency wallet credentials or initiate unauthorized transfers. The domain is currently under investigation but remains accessible and potentially harmful to unprotected users. Given the absence of detections on VirusTotal and the use of a legitimate SSL certificate from Let's Encrypt, it poses a deceptive appearance of legitimacy while operating outside standard security oversight. This combination of factors makes it a high-risk entry point for crypto asset theft, particularly for users interacting with decentralized storage or blockchain-based services. This domain exhibits several technical indicators that align with advanced phishing campaigns. It resolves to IP address 209.94.90.2, a known hosting infrastructure with limited historical trust scores based on domain age and registrar data. The domain was created on February 24, 2017, which may suggest an attempt to appear established, though this is not uncommon for reused or repurposed domains in phishing operations. Registration through CSC Corporate Domains, Inc. adds a layer of legitimacy due to the registrar's corporate focus, potentially masking malicious intent. VirusTotal currently shows 17/95 detections, indicating that mainstream security tools have not yet flagged the domain, likely due to its recent or highly targeted deployment. The presence of a Let's Encrypt SSL certificate further enhances its credibility, exploiting user trust in HTTPS indicators. These characteristics suggest a sophisticated threat actor leveraging both technical and psychological vectors to deceive users. To mitigate exposure to this crypto drainer threat, users should immediately block the associated IP 209.94.90.2 at the network perimeter and disable or restrict access to IPFS gateway links referencing this CID (bafkreigitj7uo2ip62qmnl6n4tf4ammrx3kiqxl7zz7sdqy66pc7yemygi). Organizations should update browser policies to disallow direct access to IPFS dweb.link domains unless explicitly whitelisted. Enable advanced threat detection tools that monitor for wallet transaction patterns or unauthorized signature requests, as crypto drainers often rely on silent approvals. Users should verify destination domains manually, avoid interacting with unsolicited IPFS links, and use hardware wallets or isolated signing environments for high-value transactions. Given the 17/95 detection rate, this threat represents a blind spot in traditional defenses and requires proactive threat intelligence integration and user education to prevent asset loss.
网络安全情报
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| OpenDNS | bafkreigitj7uo2ip62qmnl6n4tf4ammrx3kiqxl7zz7sdqy66pc7yemygi.ipfs.dweb.link |
phishing | Phishing Block |
| DNS4EU | bafkreigitj7uo2ip62qmnl6n4tf4ammrx3kiqxl7zz7sdqy66pc7yemygi.ipfs.dweb.link |
malicious | Sinkholed |
| Hagezi Threat Feed | www.kosherbh.com |
malicious | Sinkholed |
| DNS4EU | www.kosherbh.com |
malicious | Sinkholed |
威胁响应 Pipeline
公共封禁名单状态
所用技术 · 3 identified
IPFS is a peer-to-peer hypermedia protocol that provides a distributed hypermedia web.
ipfs.tech 置信度 100%Cloudflare is a web-infrastructure and website-security company, providing content-delivery-network services, DDoS mitigation, Internet security, and distributed domain-name-server services.
www.cloudflare.com 置信度 100%HTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org 置信度 100%VirusTotal 分析
存档证据
网站性能分析
Google PageSpeed Insights — mobile performance audit of bafkreigitj7uo2ip62qmnl6n4tf4ammrx3kiqxl7zz7sdqy66pc7yemygi.ipfs.dweb.link · checked Apr 25, 2026
证据与外部报告
您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。