bafybeiaoulkqm54mkpjy5t7idjlc2wxddyj7a4cpdrpi4reejwkd4gphke[.]ipfs[.]dweb[.]link
“Lets GOU! – Goummunity Takeover”
bafybeiaoulkqm54mkpjy5t7idjlc2wxddyj7a4cpdrpi4reejwkd4gphke.ipfs.dweb.link — 未验证. 证据摘要: VirusTotal 16/91 (alphaMountain.ai, BitDefender, Chong Lua Dao, CRDF, CyRadar); 1 external blocklist match (ScamSniffer); PhishDestroy score 100/100. 注册商: CSC.
为保留原始取证记录,下方的 PhishDestroy AI 详细分析仍使用英文。
The domain bafybeiaoulkqm54mkpjy5t7idjlc2wxddyj7a4cpdrpi4reejwkd4gphke.ipfs.dweb.link is currently active and has been identified as a generic phishing operation. Infrastructure analysis shows the domain resolves to the IP address 209.94.90.3, which is hosted in the United States and belongs to AS40680 (Protocol Labs). The site is served through Cloudflare, using HTTP/3, and the authoritative nameservers are clarissa.ns.cloudflare.com and tate.ns.cloudflare.com. A Let’s Encrypt certificate (Issuer: E7) secures the HTTPS connection, but the HTTP response returns a 301 redirect, indicating a possible attempt to forward visitors to a malicious landing page.
The page title observed is "Lets GOU! – Goummunity Takeover," offering no additional context about the spoofed brand or content. Registrant information lists CSC Corporate Domains, Inc. as the registrar, and the domain was originally created on 24 February 2017, suggesting long‑term reuse of the namespace. Reputation signals are poor: Scamadviser assigns a trust score of 20 out of 100, and the domain appears on two security blocklists (PhishDestroy and ScamSniffer).
VirusTotal analysis reports 12 of 91 scanning engines flag the domain, reinforcing the malicious classification. While the exact phishing payload or credential‑harvesting mechanism remains unverified, the convergence of a low trust score, multiple vendor detections, and blocklist listings provides strong evidence of malicious intent. Defenders should block the domain at network perimeter, update URL filtering and threat intelligence feeds, and monitor for any related activity originating from the same IP or Cloudflare edge. Continuous re‑evaluation is advised, as the site may evolve its tactics or host additional malicious content.
安全信号
威胁响应 Pipeline
公共封禁名单状态
所用技术 · 2 identified
Cloudflare is a web-infrastructure and website-security company, providing content-delivery-network services, DDoS mitigation, Internet security, and distributed domain-name-server services.
www.cloudflare.com 置信度 100%HTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org 置信度 100%VirusTotal 分析
存档证据
证据与外部报告
您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。