bafkreifki2x2ookbrn2vujr5dnx5tjeg77legdonbtfy2vhul2dt64yely.ipfs.dweb.link
Categoria: Phishing
Per usare il prodotto con tutte le funzionalità, devi acquistare una licenza di Combo Cleaner. È disponibile una prova gratuita limitata di sette giorni. Combo Cleaner è di proprietà e gestito da RCS LT, la società madre di PCRisk.com.
Quttera Web Malware Removal è un servizio in abbonamento a pagamento. Prezzi, piani e disponibilità della prova sono stabiliti da Quttera. Quttera è gestita da Quttera Ltd, una società terza indipendente non collegata a RCS LT. PCrisk.com può ricevere una commissione di segnalazione quando gli utenti si registrano tramite questo link.
Descrizione di bafkreifki2x2ookbrn2vujr5dnx5tjeg77legdonbtfy2vhul2dt64yely.ipfs.dweb.link
This URL appears to be an IPFS-hosted page delivered through a public gateway rather than a conventional branded website. The page shown in the screenshot presents itself as a generic "Webmail" login portal with username and password fields, a "Session Expired" message, and text referencing IMAP authentication and quarantined messages. It also references Roundcube-related assets, which suggests it may be imitating or repurposing a webmail interface.
Based on the domain structure and page content, this does not appear to be a normal corporate homepage or established consumer service. Instead, it appears to be a single-purpose login page hosted on decentralized storage infrastructure, with no clear operator identity shown on the page. The use of an IPFS content identifier in the hostname and the lack of visible organizational branding make attribution difficult based on available data.
Valutazione sicurezza di bafkreifki2x2ookbrn2vujr5dnx5tjeg77legdonbtfy2vhul2dt64yely.ipfs.dweb.link
Multiple scan signals indicate elevated risk at the time of this scan. The URL was flagged by 15 out of 92 security engines, with many of those detections classifying it as phishing or malicious. The page content also matches a common credential-harvesting pattern: a sparse webmail login form, urgency-themed messaging about session expiry and quarantined messages, and no clear evidence of a legitimate mail provider identity.
The malware scan also reported malicious findings associated with the page and several linked IPFS-hosted resources. While blacklist databases listed in the scan were clean at the time of review, that does not outweigh the broader multi-engine phishing consensus and the suspicious login-focused content shown in the screenshot. The combination of decentralized hosting, generic webmail branding, and credential-entry prompts may increase the likelihood that the page is intended to collect usernames and passwords.
Based on these findings, this website may pose potential risks to visitors.
Descrizione tecnica
The site is served over HTTPS with a valid Let's Encrypt certificate that was valid at the time of this scan. It resolves to infrastructure associated with Protocol Labs and uses the server banner "@helia/service-worker-gateway/3.3.1#HEAD@a1c3b15," which is consistent with an IPFS gateway setup. The domain uses Cloudflare nameservers, and DNSSEC appears to be unsigned.
From a security perspective, the main concern is not the TLS setup but the hosting model and page behavior. IPFS gateway URLs can make operator identification and takedown more difficult, and this page pulls multiple external CSS resources from other IPFS gateway hostnames that were also flagged by malware scanning. The domain itself is old, but because this is content-addressed gateway hosting, the age of the parent domain is less reassuring than it would be for a conventional standalone website.
Condividi la tua esperienza con questo sito web. Era sicuro? Hai riscontrato problemi?