bafybeihx7zpcybjq34jdy2tk2tjh6q5lw6l32p22pluszrqclrjuharkj4[.]ipfs[.]dweb[.]link
“410 Gone”
bafybeihx7zpcybjq34jdy2tk2tjh6q5lw6l32p22pluszrqclrjuharkj4.ipfs.dweb.link — 内容不可用. 证据摘要: VirusTotal 14/95 (ADMINUSLabs, alphaMountain.ai, BitDefender, CRDF, CyRadar); Google Safe Browsing flagged; PhishDestroy score 97/100. 注册商: CSC.
为保留原始取证记录,下方的 PhishDestroy AI 详细分析仍使用英文。
Analysis as of July 24, 2026 indicates that the domain bafybeihx7zpcybjq34jdy2tk2tjh6q5lw6l32p22pluszrqclrjuharkj4.ipfs.dweb.link is associated with a high‑risk generic phishing operation. The site currently returns an HTTP 410 Gone status and its page title is listed as "410 Gone," suggesting the content has been removed or deliberately disabled. The domain was registered on February 24, 2017 through CSC Corporate Domains, Inc., and its DNS resolution points to IP address 209.94.90.2, which is owned by Protocol Labs (AS40680) and geolocated to the United States. Cloudflare provides the authoritative nameservers clarissa.ns.cloudflare.com and tate.ns.cloudflare.com, and the hosting environment advertises support for HTTP/3.
A Let's Encrypt certificate (E7) is present, confirming the use of valid TLS for HTTPS connections. Google Safe Browsing has flagged the domain for social engineering, and PhishDestroy lists it as blocked. VirusTotal reports that 14 of 95 scanned security vendors have flagged the domain, indicating a consensus of malicious behavior among multiple antivirus engines. The site appears on a single external blocklist and has a Scamadviser trust score of 1 out of 100, reinforcing its classification as highly untrustworthy.
Uncertainty remains regarding the specific phishing campaign payload, the targeted brand or credential set, and whether any active phishing pages were previously hosted prior to the 410 response. Defenders should continue to monitor the domain’s IP and DNS records for any reactivation, enforce blocklist rules to deny traffic to 209.94.90.2, and incorporate the domain hash into threat‑intel feeds. Organizations using web filtering should retain the Google Safe Browsing and PhishDestroy alerts, and SOC analysts should treat any future activity from this domain as a high‑confidence indicator of phishing intent.
安全信号
威胁响应 Pipeline
公共封禁名单状态
所用技术 · 2 identified
Web infrastructure and security company providing CDN, DDoS mitigation, and DNS services.
www.cloudflare.comThird major version of HTTP protocol, built on QUIC for faster, more reliable connections.
VirusTotal 分析
存档证据
网站配置分析
证据与外部报告
您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。