bafybeiggz6dqazxzfycs7zdyecmxgbqiq3ijngxhh6wuw4qawrvq6towcq[.]ipfs[.]dweb[.]link
“ELEVEN TEST”
bafybeiggz6dqazxzfycs7zdyecmxgbqiq3ijngxhh6wuw4qawrvq6towcq.ipfs.dweb.link — 未验证. 证据摘要: VirusTotal 7/91 (ADMINUSLabs, alphaMountain.ai, CRDF, Emsisoft, Fortinet); 2 external blocklist matches (MetaMask, SEAL); PhishDestroy score 85/100. 注册商: CSC.
为保留原始取证记录,下方的 PhishDestroy AI 详细分析仍使用英文。
This domain, bafybeiggz6dqazxzfycs7zdyecmxgbqiq3ijngxhh6wuw4qawrvq6towcq.ipfs.dweb.link, was registered on May 11, 2026 through CSC Corporate Domains, Inc. The registration is recent and the domain remains active. The site resolves to the IP address 209.94.90.2, which is owned by Protocol Labs in the United States. The TLS certificate is issued by Let’s Encrypt and is currently valid. Network analysis shows the domain is served via Cloudflare, using the authoritative name servers clarissa.ns.cloudflare.com and tate.ns.cloudflare.com. HTTP requests receive a 301 redirect response, suggesting the site may be forwarding visitors to another location. VirusTotal scans report five out of ninety‑five security vendors flagging the domain, and the site appears on three external blocklists, including PhishDestroy and SEAL. Gridinsoft assigns a trust score of zero out of one hundred, indicating a high likelihood of malicious use. The only visible content is the page title “ELEVEN TEST”, providing no direct indication of the payload or lure employed. No additional landing page details, form fields, or credential‑harvesting scripts have been captured, leaving the exact phishing technique and target audience uncertain. The lack of observable malicious code may be intentional, relying on dynamic content delivery after initial page load. Defenders should add the domain and its resolving IP address to network deny lists and configure DNS filters to block any resolution attempts. Continuous monitoring for changes in HTTP response codes, content, or additional redirects is advised, as the threat actor may activate a credential‑stealing page at a later time. Incident response teams should also watch for email campaigns that reference “ELEVEN TEST” or similar branding, and correlate any observed login attempts with this infrastructure.
威胁响应 Pipeline
公共封禁名单状态
域名情报
技术细节DNS、SSL SAN、时间戳
VirusTotal 分析
证据与外部报告
您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。