bafkreifki2x2ookbrn2vujr5dnx5tjeg77legdonbtfy2vhul2dt64yely.ipfs.dweb.link
Kategorie: Phishing
Um das Produkt mit vollem Funktionsumfang zu nutzen, müssen Sie eine Lizenz für Combo Cleaner erwerben. Eine eingeschränkte kostenlose siebentägige Testversion ist verfügbar. Combo Cleaner ist Eigentum von RCS LT und wird von diesem Unternehmen betrieben, der Muttergesellschaft von PCRisk.com.
Quttera Web Malware Removal ist ein kostenpflichtiger Abonnementdienst. Preise, Tarife und die Verfügbarkeit einer Testversion werden von Quttera festgelegt. Quttera wird von Quttera Ltd betrieben, einem unabhängigen Drittunternehmen ohne Verbindung zu RCS LT. PCrisk.com kann eine Vermittlungsprovision erhalten, wenn sich Nutzer über diesen Link anmelden.
Beschreibung von bafkreifki2x2ookbrn2vujr5dnx5tjeg77legdonbtfy2vhul2dt64yely.ipfs.dweb.link
This URL appears to be an IPFS-hosted page delivered through a public gateway rather than a conventional branded website. The page shown in the screenshot presents itself as a generic "Webmail" login portal with username and password fields, a "Session Expired" message, and text referencing IMAP authentication and quarantined messages. It also references Roundcube-related assets, which suggests it may be imitating or repurposing a webmail interface.
Based on the domain structure and page content, this does not appear to be a normal corporate homepage or established consumer service. Instead, it appears to be a single-purpose login page hosted on decentralized storage infrastructure, with no clear operator identity shown on the page. The use of an IPFS content identifier in the hostname and the lack of visible organizational branding make attribution difficult based on available data.
Sicherheitsbewertung für bafkreifki2x2ookbrn2vujr5dnx5tjeg77legdonbtfy2vhul2dt64yely.ipfs.dweb.link
Multiple scan signals indicate elevated risk at the time of this scan. The URL was flagged by 15 out of 92 security engines, with many of those detections classifying it as phishing or malicious. The page content also matches a common credential-harvesting pattern: a sparse webmail login form, urgency-themed messaging about session expiry and quarantined messages, and no clear evidence of a legitimate mail provider identity.
The malware scan also reported malicious findings associated with the page and several linked IPFS-hosted resources. While blacklist databases listed in the scan were clean at the time of review, that does not outweigh the broader multi-engine phishing consensus and the suspicious login-focused content shown in the screenshot. The combination of decentralized hosting, generic webmail branding, and credential-entry prompts may increase the likelihood that the page is intended to collect usernames and passwords.
Based on these findings, this website may pose potential risks to visitors.
Technische Beschreibung
The site is served over HTTPS with a valid Let's Encrypt certificate that was valid at the time of this scan. It resolves to infrastructure associated with Protocol Labs and uses the server banner "@helia/service-worker-gateway/3.3.1#HEAD@a1c3b15," which is consistent with an IPFS gateway setup. The domain uses Cloudflare nameservers, and DNSSEC appears to be unsigned.
From a security perspective, the main concern is not the TLS setup but the hosting model and page behavior. IPFS gateway URLs can make operator identification and takedown more difficult, and this page pulls multiple external CSS resources from other IPFS gateway hostnames that were also flagged by malware scanning. The domain itself is old, but because this is content-addressed gateway hosting, the age of the parent domain is less reassuring than it would be for a conventional standalone website.
Teilen Sie Ihre Erfahrung mit dieser Website. War sie sicher? Sind Probleme aufgetreten?